Breaches · 109 days ago
Carnival’s breach is still not fully bounded. The company has now moved from a claimed April theft to formal notification, but the 5,995,277-person notice does not match the larger public dump, which points to duplicate records or extra loyalty data beyond the confirmed set.
Carnival says an employee account was reached through social engineering, which gave access to a limited internal system and led to copying of personal information. The leak was reported at 8.7 million records, and analysis tied part of it to the Mariner Society loyalty program, with names, dates of birth, email addresses, gender, location data, and loyalty details among the exposed fields.
The open question is scope, not attribution. If the leak includes duplicates or subsidiary records outside the formal notice, the breach reaches deeper into Carnival’s brand and loyalty structure than the notice count shows.
4 sources covering this story
Carnival Data Breach Exposed 6 Million People
Data breach leaves nearly 6 million Carnival customers navigating identity theft risks.
Cybercriminals sail away with data from 6 million Carnival customers - Help Net Security
Carnival Corporation confirmed a data breach weeks after the ShinyHunters hacking group claimed it had stolen millions of customer records.
The Record from Recorded Future
Cruise giant Carnival confirms data breach affecting nearly 6 million people
By the end of April, Carnival determined that the attacker had copied personal information from its systems.
Carnival Cruise confirms data breach affecting nearly 6 million people
Carnival Corporation, the world's largest cruise line operator, has confirmed a data breach affecting nearly 6 million people claimed by the ShinyHunters extortion gang in April 2026.
Part of the PlainSec briefing for 2026-05-28