Carnival Corporation says an unauthorized actor accessed a limited portion of its IT system in April 2026, affecting nearly 6 million people. Multiple outlets report that Carnival identified the incident on April 14, after unauthorized activity involving an employee account was detected. Sources describe the intrusion as resulting from social engineering, in which a bad actor deceives an employee to gain access.
Several reports trace the breach to claims and interest by outside groups. TechRadar and other coverage note that the ShinyHunters group publicly claimed responsibility in late April. Carnival later confirmed that an illegal access occurred and that certain personal information was exposed.
The accessed data is reported to include customer details such as names, addresses, email and phone numbers, date of birth, and identification information including passport or driver’s license numbers. Carnival says it acted to block the unauthorized activity and began working with third-party security experts while investigating the scope of the incident.
Per outlets citing Carnival’s notices, affected individuals are notified starting May 27. Carnival offers access to credit monitoring through TransUnion, along with guidance to remain vigilant for fraud or identity theft.