Carnival Confirms Data Breach Affecting Nearly 6 Million People After Social-Engineering Attack as ShinyHunters Claims the Records
Carnival told Maine's attorney general that 5,995,277 people were affected by an April breach traced to a compromised employee account; ShinyHunters claims the data.
Overview
Carnival Corporation, the world’s largest cruise operator, has confirmed a data breach that affected nearly 6 million people, tracing the intrusion to a single compromised employee account. In a filing with the Maine attorney general’s office, the company reported that 5,995,277 people were affected, according to SecurityWeek. The cruise line began notifying those individuals in late May, and the data-extortion group ShinyHunters has claimed responsibility for the theft.
What We Know
Carnival said the incident was identified on April 14, after attackers gained access to an employee’s account through social engineering, as reported by SecurityWeek. According to the company’s breach notice cited by BleepingComputer, “An unauthorized actor used social engineering to deceive an employee to gain access to a limited portion of the Company’s IT system.” The same notice states that the initial access occurred on April 10, and that on April 22, 2026, the company “first determined that the bad actor illegally copied personal information,” per BleepingComputer.
The number of affected people comes from a filing with the Maine attorney general’s office, which puts the figure at just under six million, as reported by The Register. Carnival began notifying 5,995,277 customers, according to BleepingComputer.
The exposed information varies by individual but generally includes names, addresses, dates of birth, email addresses, phone numbers, and government-issued ID numbers, according to SecurityWeek. The Record reported that the stolen data set varies by person and, in its account, includes names, addresses, email addresses, phone numbers, dates of birth, driver’s license numbers and passport numbers, per The Record.
Carnival said it is providing affected individuals with 24 months of free credit monitoring, according to SecurityWeek. The Register reported that the two years of credit monitoring are being offered through TransUnion.
In a statement, the company said it had moved quickly to contain the intrusion. “We acted swiftly to block the unauthorized activity and immediately began working with third-party security experts,” Carnival said, as quoted by The Record. The company also said it has since hardened its environment: “In addition to the comprehensive security measures the company had in place prior to the incident, it has taken steps to further safeguard its systems, including enhancing its security and monitoring controls,” according to The Register.
The ShinyHunters Claim
The data-extortion group ShinyHunters has claimed responsibility for the breach. In April, ShinyHunters said it had obtained a large volume of Carnival data, as reported by The Record. The group claimed the theft of 8.7 million records from Carnival’s systems and made the data publicly available in late April, according to SecurityWeek. ShinyHunters said it stole documents containing over 8.7 million records with personally identifiable information and terabytes of internal corporate data, according to BleepingComputer.
The number Carnival reported to Maine regulators is lower than the figure the group circulated: the Maine filing of just under six million is down from the 8.7 million records previously listed by Have I Been Pwned, according to The Register. The Register also reported that the group “hinted at a breakdown in negotiations, likely related to the criminal outfit’s extortion demands,” and quoted the attackers as saying, “The company failed to reach an agreement with us despite our incredible patience,” per The Register.
What We Don’t Know
Carnival has not publicly attributed the attack to ShinyHunters, according to The Record. The company declined to comment on the scale of the breach or to name ShinyHunters, as reported by The Register. The full breakdown of which data categories were exposed for each affected individual was not detailed in the company’s public statements, and the outcome of any extortion negotiations has not been disclosed.
Context
The breach adds to a series of incidents the cruise operator has disclosed over the years. Since 2020, Carnival has disclosed several data breaches; the company was hacked in 2019, fell victim to a ransomware attack in 2020, and was hacked again in March 2021, according to SecurityWeek.
The incident also fits a broader pattern of breaches that begin with a tricked employee rather than a software flaw. In this case, the attackers did not exploit a vulnerability but persuaded a worker to hand over access, after which they reached a limited portion of Carnival’s IT environment, as reported by The Record.