LmCast :: Stay tuned in

Carnival Cruise confirms data breach affecting nearly 6 million people

Recorded: May 28, 2026, 11 a.m.

Original Summarized

Carnival Cruise confirms data breach affecting nearly 6 million people

News

Featured
Latest

Glassworm botnet disrupted after resilient C2 infrastructure takedown

CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

Windows 11 KB5089573 update released with performance improvements

Charter confirms data breach after ShinyHunters extortion threat

Carnival Cruise confirms data breach affecting nearly 6 million people

Sextortionist sentenced to 33 years for targeting 145 children

GPU mining malware spreads via SEO poisoning, AI chatbots

This CompTIA IT learning path is only $40 through 6/14

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCarnival Cruise confirms data breach affecting nearly 6 million people

Carnival Cruise confirms data breach affecting nearly 6 million people

By Sergiu Gatlan

May 28, 2026
06:49 AM
0

Carnival Corporation, the world's largest cruise line operator, has confirmed a data breach affecting nearly 6 million people claimed by the ShinyHunters extortion gang in April 2026.
The cruise line giant has over 160,000 employees and served around 13.5 million guests in 2024 via a fleet of over 90 ships.
Carnival operates nine of the world's leading cruise line brands (Carnival Cruise Line, Costa, P&O Australia, P&O Cruises, Princess Cruises, Holland American Line, AIDA, Cunard, and Seabourn) and a travel tour company (Holland America Princess Alaska Tours), and it reported revenues of over $26 billion last year.
The company started notifying 5,995,277 customers on Wednesday that threat actors stole their data in an April 10 breach after gaining access to some of its IT systems in a social engineering attack.
"On April 14, 2026, the Company's IT security team identified unauthorized activity involving an employee's account. An unauthorized actor used social engineering to deceive an employee to gain access to a limited portion of the Company's IT system," the company said in data breach notification letters sent to affected individuals.
"The Company acted swiftly to block the unauthorized activity and immediately began working with third party security experts to further strengthen our security and to conduct a thorough investigation. On April 22, 2026, the Company first determined that the bad actor illegally copied personal information."
While Carnival has yet to attribute the attack, the ShinyHunters cybercrime group claimed responsibility for the breach in April, saying they stole documents containing over 8.7 million records with personally identifiable information and terabytes of internal corporate data.

Carnival on ShinyHunters leak site (BleepingComputer)
Although a Carnival spokesperson didn't reply when BleepingComputer reached out to confirm ShinyHunters' claims and for more details on what data was stolen in the attack, data breach notification service Have I Been Pwned analyzed the data leaked by the extortion gang and said the breach exposed affected people's names, dates of birth, email addresses, genders, geographic locations, and loyalty program details.
"The data contained fields indicating it related to the Mariner Society loyalty program run by Holland America, a cruise line brand under Carnival, and included names, dates of birth, genders and data relating to status within the loyalty program," Have I Been Pwned noted.
Over the past year, ShinyHunters has been targeting Salesforce customers and has breached hundreds of companies worldwide, claiming to have stolen billions of records in the Salesloft Drift campaign and the Salesforce Aura data theft attacks.
The FBI advised ShinyHunters' victims two weeks ago not to pay the attackers' ransom demands, after previously warning that doing so does not guarantee the threat actors won't attempt to extort the victims again or sell the stolen data to other cybercriminals.
Carnival Corporation disclosed other data breaches in March 2020 and June 2021 that exposed personal and financial information belonging to customers, employees, and crew after threat actors gained access to Carnival employees' email accounts.
Ransomware gangs also stole the personal information of Carnival customers and employees after breaching the company's systems in August 2020 and December 2020.

The Validation Gap: Automated Pentesting Answers One Question. You Need Six.

Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.This guide covers the 6 surfaces you actually need to validate.
Download Now

Related Articles:
7-Eleven data breach exposes personal information of 185,000 people7-Eleven confirms data breach claimed by the ShinyHunters gangInstructure reaches 'agreement' with ShinyHunters to stop data leakHome security giant ADT data breach affects 5.5 million peopleData breach at edtech giant McGraw Hill affects 13.5 million accounts

Breach
Carnival
Cruise
Data Breach
ShinyHunters

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

Anthropic’s restricted Claude Mythos model may be coming to Claude Code

Microsoft Defender can now automatically isolate hacked endpoints

Sponsor Posts

Protect Your Business from Ecommerce Fraud

Overdue a password health-check? Audit your Active Directory for free

33% Rise in Healthcare Credential Theft in 2025: What you need to know

AI is a data-breach time bomb: Read the new report

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Carnival Corporation, the world's largest cruise line operator, confirmed a significant data breach in April 2026, following an extortion threat by the ShinyHunters cybercrime group. This incident reportedly affected nearly six million individuals. The breach originated when threat actors successfully gained access to some of the company's IT systems through a social engineering attack targeting an employee account. The company’s IT security team identified unauthorized activity involving an employee's account on April 14, 2026, and subsequently determined that a bad actor had illegally copied personal information on April 22, 2026, after the company worked with third-party security experts to investigate the unauthorized activity.

The ShinyHunters cybercrime group subsequently claimed responsibility for the breach, asserting that they stole documents containing over eight point seven million records of personally identifiable information and terabytes of internal corporate data. Analysis conducted by the data breach notification service Have I Been Pwned revealed that the exposed data included sensitive details such as names, dates of birth, email addresses, genders, geographic locations, and loyalty program details associated with the Mariner Society loyalty program, which is operated by Holland America, a cruise line brand under Carnival.

In addition to the specific breach, the context of data security at Carnival involves prior incidents; the corporation had previously disclosed data breaches in March 2020 and June 2021, which involved the exposure of personal and financial information belonging to customers, employees, and crew after threat actors accessed employee email accounts. Furthermore, ransomware gangs also successfully stole the personal information of Carnival customers and employees after breaching the company's systems in August and December 2020. The FBI had previously advised ShinyHunters' victims not to comply with ransom demands, warning that payment does not guarantee the threat actors will cease extortion or refrain from selling the stolen data to other cybercriminals. This case highlights the ongoing challenges in validating security controls, as automated penetration testing tools are designed to answer singular questions about network movement rather than comprehensive validation of threat blocking, detection rules, or cloud configurations.