
Carnival Corporation, the world's largest cruise operator, has confirmed a data breach that exposed personal information of approximately six million people, according to filings made public on May 28, 2026. The company began sending "Notice of Cybersecurity Event" letters dated May 27, weeks after extortion group ShinyHunters listed Carnival on its "pay or leak" portal.
How the Attack Unfolded
Carnival said its IT security team identified unauthorized activity involving an employee's account on April 14, 2026. "An unauthorized actor used social engineering to deceive an employee and gain access to a limited portion of the company's IT system," the company stated. By April 22, the attacker had used the compromised account to access internal systems and copy files containing personal data before being blocked.
According to a data breach notice filed with the Maine attorney general's office, 5,995,277 individuals were affected. Stolen records, cited by researchers, include full names, email addresses, dates of birth, gender, Mariner Society loyalty program tier and internal customer identifiers; SecurityWeek added that government-issued ID numbers and phone numbers were also in scope for some individuals.
ShinyHunters Claims Responsibility
The extortion group ShinyHunters, which has been linked to a string of high-profile breaches in 2026, claimed the attack. According to Have I Been Pwned, ShinyHunters listed Carnival on April 18 and advertised 8.7 million records containing 7.5 million unique email addresses, much of it tied to the Mariner Society program operated by Carnival subsidiary Holland America Line. ShinyHunters typically steals data, demands payment, and then sells or leaks records when victims refuse.
Customer Response and Mitigation
Carnival is offering eligible U.S. residents two years of complimentary credit monitoring through TransUnion's MyTrueIdentity platform, with fraud assistance from Cyberscout. The company said it has added new security and monitoring controls and "will continue advancing its IT security and data privacy controls to address evolving threats."
It is not Carnival's first incident. Between 2019 and 2021 alone, the cruise giant disclosed four separate cybersecurity events to the New York Department of Financial Services, including two ransomware attacks and a phishing incident that resulted in malware deployment and data theft.
Part of a Wider Surge in Identity-Based Attacks
The Carnival breach is the latest in a wave of social-engineering and identity-driven incidents striking large enterprises in 2026. A Gitea flaw recently exposed 30,000 private container registries, while Anthropic's Claude Mythos surfaced 10,000 software flaws in a single sweep. Defense agencies are increasing their AI bet too, with Pentagon AI use jumping 1,775% as the DoD orders 200,000 drones.
Advice for Affected Customers
Security firms recommend that Carnival customers treat any unsolicited message claiming to be from the company or from a credit-monitoring vendor as suspicious. Enrolling in the offered monitoring, enabling multi-factor authentication on related accounts and reviewing financial statements for unusual activity are prudent steps. Carnival has not publicly disclosed which specific data fields apply to each individual, with notification letters using a placeholder for the elements obtained.
Reporting based on coverage from Help Net Security, Malwarebytes and SecurityWeek.