Description

Carnival Corporation, the world’s largest cruise line operator, has confirmed a major data breach affecting nearly 6 million individuals following a cyberattack claimed by the ShinyHunters extortion gang in April 2026. The company, which operates nine leading cruise brands including Carnival Cruise Line, Princess Cruises, Cunard, and Holland America Line, reported that attackers gained access to a limited section of its Attack on IT systems by a social engineering attack on the employee's account. Carnival serves around 13.5 million guests annually and generated more than $26 billion in revenue last year. According to breach notification letters sent to 5,995,277 affected customers, Carnival’s IT security team detected unauthorized activity on April 14, 2026. The company stated that cybercriminals deceived an employee into providing access to internal systems. Carnival immediately blocked the unauthorized activity, launched an investigation with external cybersecurity experts, and later confirmed on April 22 that personal data had been illegally copied. Although the company has not officially attributed the attack to any group, ShinyHunters publicly claimed responsibility and alleged that it stole over 8.7 million records along with terabytes of internal company data. Data breach tracking service Have I Been Pwned reported that the leaked information included names, dates of birth, email addresses, genders, geographic locations, and loyalty program details linked to Holland America’s Mariner Society program. This is one of many attacks in a larger campaign run by ShinyHunters, who extort and steal data from Salesforce customers and other major companies across the globe. This is not Carnival’s first cybersecurity incident. The company previously disclosed breaches in 2020 and 2021 involving customer and employee information, while ransomware attacks in 2020 also exposed sensitive personal data. The FBI has recently advised victims of ShinyHunters not to pay ransom demands, warning that payments do not guarantee stolen data will be deleted or protected from further misuse.