Carnival’s breach is still not fully bounded. The company has now moved from a claimed April theft to formal notification, but the 5,995,277-person notice does not match the larger public dump, which points to duplicate records or extra loyalty data beyond the confirmed set.
Carnival says an employee account was reached through social engineering, which gave access to a limited internal system and led to copying of personal information. The leak was reported at 8.7 million records, and analysis tied part of it to the Mariner Society loyalty program, with names, dates of birth, email addresses, gender, location data, and loyalty details among the exposed fields.
The open question is scope, not attribution. If the leak includes duplicates or subsidiary records outside the formal notice, the breach reaches deeper into Carnival’s brand and loyalty structure than the notice count shows.