Carnival Corporation officially confirmed a significant data breach in 2026. The incident, linked to the hacker group ShinyHunters, occurred on April 10, 2026, and was detected through social engineering targeting an employee account. Carnival Corporation confirmed the exposure of personal information for nearly 6 million individuals.
The breach involved data types including full names, addresses, email addresses, phone numbers, dates of birth, government-issued ID numbers (such as driver's license and passport details), and loyalty program membership information. While no SSN or financial account credentials were compromised, the exposure of passport and ID details poses a high risk of identity theft. The exact number of affected individuals is 5,995,277, as confirmed by a Maine Attorney General filing.
Details about this incident may continue to emerge. Companies often provide additional information as their investigations progress, and notification processes can be delayed.