Cybercriminals steal data of 6 million Carnival customers

▼ Summary
– Carnival Corporation confirmed a data breach after ShinyHunters claimed to have stolen millions of customer records, with the breach originating from a phishing attack on a single employee account.
– The hacked data included 8.7 million records with 7.5 million unique email addresses, linked to the Holland America Line Mariner Society loyalty program.
– Exposed information comprised names, dates of birth, genders, email addresses, and loyalty program status.
– Carnival filed a notice with Maine authorities stating the incident affected 5,995,277 people and began notifying individuals on May 27, 2026, offering credit monitoring.
– Carnival enhanced security and monitoring controls after the breach, which is not the first cyberattack on its systems.
One of the world’s leading cruise operators, Carnival Corporation, has confirmed a data breach exposing the personal information of approximately 6 million customers, weeks after the notorious ShinyHunters hacking group claimed responsibility for stealing millions of records.
The company disclosed that the incident stemmed from a phishing attack targeting a single employee account. Carnival stated it is actively investigating the full extent of the unauthorized access.
“On April 14, 2026, the company’s IT security team identified unauthorized activity involving an employee’s account. An unauthorized actor used social engineering to deceive an employee and gain access to a limited portion of the company’s IT system,” Carnival explained in a statement.
According to data breach tracking service Have I Been Pwned, ShinyHunters posted Carnival Corporation on its “pay or leak” portal on April 18, claiming possession of stolen customer data. The group alleged the leak contained 8.7 million records, including 7.5 million unique email addresses, with fields pointing to the Mariner Society loyalty program operated by Holland America Line, a Carnival subsidiary.
The compromised data reportedly includes names, dates of birth, genders, email addresses, and details about loyalty program status. However, Carnival’s official data breach notice filed with Maine authorities states that the incident affected 5,995,277 individuals.
Carnival began notifying impacted customers on May 27, 2026. Eligible U. S. residents are being offered two years of complimentary credit monitoring services through TransUnion as part of the response.
“In addition to the security measures already in place before the incident, the company has taken steps to further safeguard its systems, including enhancing its security and monitoring controls. The company will continue advancing its IT security and data privacy controls to address evolving threats,” Carnival concluded.
This breach raises serious questions about Carnival’s cybersecurity posture. It is not the first time the company has fallen victim to cybercriminals, and customers will be watching closely to see if these promised enhancements truly prevent a repeat incident.
(Source: Help Net Security)



