Carnival Breach Exposes Passenger ID…Carnival Breach Exposes Passenger ID DataCoverage from Fox News, Chinook Observer, and others
00/00/0000
DailyWeekly
Carnival Corporation disclosed that an attacker used social engineering to compromise an employee account and access a limited portion of its IT environment in April 2026.
The company later determined that personal information had been copied, potentially affecting nearly 6 million people, with exposed data varying by individual and including government-issued identification details. Carnival is notifying affected individuals, offering U.S. customers two years of credit monitoring, and investigating the incident with outside experts, while ShinyHunters has claimed responsibility without public attribution from Carnival.
Looking Back
109 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Apr 19
May 7
May 25
Jun 12
Jun 30
Jul 18
Aug 5
History
07/28/2026
The update adds that ShinyHunters attempted extortion and that Carnival still has not publicly attributed the breach to the group. It also sharpens the exposure picture by naming the Texas filing and the scale of Texans potentially affected.
07/27/2026
The update adds concrete disclosure details around the breach’s scope, affected data, and remediation, while dropping earlier emphasis on ShinyHunters-driven extortion and litigation. The story is now centered more on confirmed exposure of sensitive identifiers and official notification actions, including a large Texas resident count.