Carnival Corporation disclosed a data breach after a threat actor used social engineering to compromise an employee account and gain unauthorized access to a limited portion of the company’s internal IT systems. The company said it detected suspicious activity on April 14, contained the intrusion with help from third-party cybersecurity specialists, and confirmed by April 22 that customer personal information had been copied from affected systems.
The exposed data included names, addresses and other contact details, dates of birth, government-issued identification numbers linked to passports and driver’s licenses, and in some cases Social Security numbers. Reports said about 6 million people in the United States may be affected. Carnival began notifying impacted individuals on May 27, issued a public notice for people it could not contact directly, and is offering 24 months of complimentary credit monitoring through TransUnion MyTrueIdentity. The company has not identified the threat actor or said whether ransomware or extortion was involved.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The ShinyHunters hacking group claimed it had stolen millions of Carnival customer records and posted the company on its pay-or-leak site. Reporting said the leaked data was tied to Holland America Line’s Mariner Society loyalty program and included personal and loyalty-related information.
A Maine breach notice cited in reporting stated that Carnival's April 2026 incident affected 5,995,277 people. The disclosure materially expanded the known scope of the breach beyond earlier notices that only described the categories of personal information copied.
Carnival began sending notification emails to affected individuals on May 27, 2026, and also issued a public notice for people it could not directly contact. The company offered 24 months of complimentary TransUnion credit monitoring to affected U.S. customers.
By April 22, 2026, Carnival had confirmed that customer personal information had been copied in the incident. Reported exposed data included names, dates of birth, contact details, and government-issued identification information, with one report also stating Social Security numbers may have been affected.
Carnival said it detected unauthorized activity on April 14, 2026, after a threat actor used social engineering to compromise an employee account and access a limited portion of its internal IT systems. The company contained the intrusion and engaged third-party cybersecurity specialists.
Carnival said threat actors gained access to its environment on April 10, 2026, after socially engineering an employee account. The access preceded the company's detection of unauthorized activity on April 14.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcexakep.ru
Open sourcetechrepublic.com
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourcetheregister.com
Open sourceteiss.co.uk
Open sourcecyber.nj.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.