Carnival Cruise Line Reports Major Data Breach Affecting Nearly 6 Million Passengers

Carnival Cruise Line has confirmed a data breach affecting nearly 6 million passengers after hackers used a "social engineering" trick to steal employee login credentials. The breach began on April 10, 2026, when a threat actor deceived a Carnival employee into handing over their account password, according to NBC Boston.
The notorious hacking group ShinyHunters has claimed responsibility, saying it stole 8.7 million records and "terabytes" of internal data, per BleepingComputer. Carnival's official filing with the Maine Attorney General puts the number of affected persons at 5,995,277 — nearly half of the 13.5 million guests the company served in all of 2025.
The attack unfolded in stages. On April 10, a hacker tricked a Carnival employee into revealing their account credentials — a tactic called "phishing." Carnival's IT team spotted the intrusion on April 14 and blocked the attacker's access. But by April 22, investigators confirmed the hacker had already copied and taken files from the company's systems, NBC Chicago reported.
Cybersecurity expert Ensar Seker, CISO at SOCRadar, warned this kind of attack is increasingly common. "Threat actors no longer need sophisticated zero-days when they can exploit human trust," he said, according to Security Magazine. "A single compromised employee account can quickly become an entry point into sensitive customer environments." Consultant Tim Howard added that AI tools now make fake calls and messages nearly impossible to detect, per NBC DFW.
Carnival says the exposed data may include names, addresses, phone numbers, email addresses, dates of birth, and government-issued ID numbers such as driver's licenses and passport numbers. Early analysis suggests the breach targeted databases tied to the Mariner Society, a loyalty program run by Holland America Line, a Carnival subsidiary, per Have I Been Pwned.
The breach is global but hits U.S. customers hardest. Over 800,000 Texans were affected, NBC Washington reported. Maine reported 9,746 residents impacted. Passengers across nine Carnival brands — including Princess Cruises, Cunard, and Seabourn — are all potentially exposed.
Carnival waited 43 days after discovering the breach — from April 14 to May 27 — before sending notification letters to victims. Legal experts say that gap left millions of people vulnerable to fraud and identity theft. Paul Bischoff of Comparitech noted that while companies often cite "law enforcement coordination" for delays, victims have no way to protect themselves in the meantime, according to NBC Philadelphia.
Making matters worse, this is not Carnival's first major breach. Between 2019 and 2021, the company reported four separate security incidents. In 2022, it paid a $1.25 million settlement tied to a 2020 breach, per NBC Bay Area. Multiple law firms have now launched investigations for possible class action lawsuits, alleging Carnival failed to properly encrypt sensitive data.
Carnival is offering 24 months of free credit monitoring and identity theft protection through TransUnion to all U.S. victims, per NBC New York. Affected passengers should watch for notification letters sent by mail or email starting May 27. Experts strongly recommend enrolling in the credit monitoring service even if you are already signed up elsewhere.
Carnival said in its official statement: "We deeply regret this incident and any concern it may cause... We acted swiftly to block the unauthorized activity and immediately began working with third-party security experts to further strengthen our security." Victims who believe their data was misused can also file complaints with their state Attorney General or the Federal Trade Commission at reportfraud.ftc.gov.
Publishers
7
Articles
6
Reach
7