Data breach
Carnival Corporation
- Records
- 7,549,875
- Breach date
- 11 April 2019Estimated
- Added
- 23 April 2026
What was exposed
3 types of data · 5 more reported
- Email addresses7,549,875
- Names6,669,991
- Dates of birth5,206,156
- Driving licence numbersReported, not counted
- Passport numbersReported, not counted
- Home addressesReported, not counted
- Phone numbersReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Carnival Corporation & plc, the world's largest cruise operator, has confirmed a data breach that exposed personal information belonging to millions of people, many of them customers of its Holland America Line brand and its Mariner Society loyalty program. The investigation team estimates the listing covers 7,549,875 records containing email addresses, along with names for 6,669,991 records and birth dates for 5,206,156 records. The team estimates the compromise occurred on April 11, 2019, while Carnival's own 2026 disclosures describe unauthorized access identified that April. Public reporting reviewed as of September 25, 2026 does not fully reconcile the two dates, and the exact dating of the underlying compromise remains unclear.
An extortion group known as ShinyHunters listed Carnival on its leak site in April 2026, claiming to hold 8.7 million records. Carnival has not publicly confirmed that ShinyHunters carried out the attack. The company has said the incident involved a social engineering attack, in which someone deceived an employee to gain access to part of its IT system through a single user account.
April 21, 2026: The "pay or leak" deadline set by ShinyHunters expired, after which the group began publishing data, according to Cruise Hive.
April 24, 2026: Cruise Hive reported that ShinyHunters claimed to have stolen more than 8.7 million records, and Carnival confirmed it was investigating unauthorized activity involving a single user account.
May 27, 2026: Carnival reported the incident publicly; state breach reporting later showed 5,995,277 people were affected, per NBC Miami.
June 5, 2026: Fox News reported that Carnival confirmed the breach affected nearly 6 million people and that notifications and credit monitoring offers were underway.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses across all 7,549,875 records, names in 6,669,991 records, and birth dates in 5,206,156 records.
Carnival's disclosure, as reported by Fox News, indicated that the information known to be involved also included addresses, phone numbers, and government-issued identification numbers such as driver's license and passport numbers, varying by individual. Reporting by TechRadar described the published dataset as tied to Holland America's Mariner Society loyalty program and noted it also included genders, geographic locations, salutations, and loyalty program details.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Names, email addresses, birth dates, and loyalty program details give scammers material for convincing, personalized phishing. Messages may reference expiring loyalty points, refunds, or cabin upgrades to appear legitimate. Because some individuals' data included driver's license or passport numbers, there is also a risk of identity theft and fraudulent account openings. Stolen contact details can support targeted calls and texts that impersonate cruise brands.
What Is Carnival Corporation Doing in Response?
Carnival said it acted quickly to shut down the unauthorized access and block further activity, engaged third-party security experts, and notified law enforcement. The company said it is notifying affected individuals and has added new layers of security and monitoring. Carnival is offering eligible U.S. individuals two years of complimentary credit monitoring, according to Fox News and NBC Miami.
What Should You Do If You Were Affected?
Watch for an email notification from Carnival and read it carefully to see what data may have involved you.
If you are eligible, enroll in the offered credit monitoring using contact details from the official notice, not links in unsolicited emails.
Change passwords on cruise and travel accounts, and use a unique password for each account. Turn on two-factor authentication where available.
Be skeptical of emails, texts, or calls about refunds, loyalty points, or account verification. Go directly to the official website instead of clicking links.
Monitor bank and credit card statements for unfamiliar charges and review your credit reports for accounts or inquiries you do not recognize.
Consider a free credit freeze with the major bureaus, especially if government ID numbers were involved.
In the news
- Fox News: Carnival breach may put your travel data at riskfoxnews.com (opens in a new tab)
- TechRadar: ShinyHunters claim to have pinched 7.5 million Carnival cruise emailstechradar.com (opens in a new tab)
- Cruise Hive: Carnival probes alleged data breach involving 8.7 million recordscruisehive.com (opens in a new tab)
- NBC Miami: Carnival data breach exposes passengers' personal informationnbcmiami.com (opens in a new tab)
