Carnival Corporation, a cruise and leisure company, experienced a cybersecurity event that led to a data breach. The incident became public knowledge in June 2026 and was acknowledged through "Notice of Cybersecurity Event" letters issued by the company.
The breach affected nearly 6 million individuals. While the company's notice confirmed the exposure of personal information, the exact full categories of data compromised, such as SSNs, medical data, or financial account data, have not been conclusively confirmed in the publicly available search snippets. A consumer notice was filed in Maine, indicating that residents of at least that state were affected; however, the full list of states impacted has not been publicly identified. Some details surrounding the breach may emerge over time as investigations continue, and affected individuals may experience delays in receiving notifications.