Data Breach
Carnival Data Breach Exposes 6 Million Travelers
Key Facts
Signal Type
Data Breach
Industry
Cybersecurity
Companies
Carnival Corporation, Holland America Line, TransUnion, ShinyHunters
Date
June 6, 2026
On April 14, 2026, Carnival Corporation detected unauthorized access to its IT systems via a social engineering attack on an employee account. By April 22, it was confirmed that personal data of nearly 6 million individuals had been illegally copied. ShinyHunters claimed responsibility for the breach, listing Carnival on its pay-or-leak portal with a ransom deadline.
The breach impacted 5,995,277 individuals, including 9,746 Maine residents. Affected data includes names, addresses, email addresses, phone numbers, dates of birth, and government-issued identification numbers. Carnival is notifying affected individuals and offering U.S. residents two years of complimentary credit monitoring through TransUnion.
Monitor how Carnival's response influences industry standards for data security. Watch for potential regulatory changes and increased investments in cybersecurity measures across the travel sector. Additionally, observe how ShinyHunters' activities evolve and impact other industries.
Source:
FTN news