EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-carnival-cruise-shinyhunters-breach
039/430

File EL-0392HighResolvedData Breach / Extortion with Data Exfiltration

Carnival Cruise Data Breach

Also filed as ShinyHunters Carnival Hack · Carnival Corporation Customer Data Leak

The ShinyHunters extortion gang breached Carnival Corporation, the world's largest cruise line operator, and stole personal information belonging to approximately 7.5 million passengers. The breach affected customers across Carnival's portfolio of cruise brands including Carnival Cruise Line, Princess Cruises, Holland America Line, and Seabourn.

  • #travel
  • #cruise-line
  • #pii
  • #customer-data
  • #loyalty-program
  • #extortion
Notoriety8/10
Event
1 Apr 2026
Disclosed
28 May 2026
Target
Carnival Corporation
Actor
ShinyHunters
Scale
7.5M people
Status
Resolved

01Summary

In April 2026, ShinyHunters gained unauthorized access to Carnival Corporation's systems and exfiltrated customer data. The stolen records included personal information from the company's loyalty programs and booking systems. Carnival confirmed the breach in late May 2026 and the data was subsequently listed on Have I Been Pwned with 7.5 million affected accounts. The breach was part of ShinyHunters' broader 2026 campaign targeting major U.S. travel, telecommunications, and healthcare companies.

02Background

Carnival Corporation is the world's largest cruise company, operating a fleet of nearly 100 ships across multiple brands. Its customer databases contain extensive personal information including passport details, frequent cruiser numbers, and payment information, making it a high-value target for cybercriminal extortion groups.

03Key revelations

  1. 01Scale of customer data held by major cruise lines across multiple brands.
  2. 02Continued success of ShinyHunters' extortion campaign against major U.S. corporations in 2026.

04Technical analysis

The attack followed ShinyHunters' established methodology, likely involving social engineering (vishing) to compromise employee credentials and gain access to internal customer databases for bulk data exfiltration.

Attack vector
Social engineering / Credential compromise
Attack method
Data exfiltration and extortion
Initial access
Social engineering (likely vishing)
Exfiltration
Bulk data extraction

05Threat actor

ShinyHunters is a prolific cybercriminal/extortion group known for targeting large corporations and high-value datasets for financial gain through data extortion.

Aliases

  • SH
  • Scattered LAPSUS$ Hunters

Attribution sources

  • ShinyHunters leak site
  • Carnival Corporation SEC filing
  • BleepingComputer
  • Have I Been Pwned

06Victims and impact

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers
  • Loyalty program data
  • Booking information

08Financial damage

Reputational damage, regulatory fines, and potential class-action lawsuits.

09Timeline

  1. 2026-04-01Approximate date of initial breach.
  2. 2026-05-28Carnival confirms breach; data listed on Have I Been Pwned (7.5M records).

10Reaction and fallout

Public reaction

Concern among cruise passengers over exposure of personal travel data and loyalty program details.

11Legal

Ongoing investigations; class-action lawsuits anticipated.

Civil lawsuits

  • Anticipated class-action lawsuits

12Significance and legacy

Significance

One of the largest breaches in the cruise and hospitality industry, affecting customers across multiple major cruise brands globally.

Legacy

Highlights the vulnerability of the travel and hospitality sector to data extortion attacks.

13Disclosure and media

Authentication
ShinyHunters leak site and Carnival Corporation SEC filing

Publishing organisations

  • BleepingComputer
  • Have I Been Pwned
  • Reuters

14Related files

Related events

  • 2026-charter-communications-shinyhunters-breach

15Field notes

  1. 01Carnival operates nearly 100 cruise ships across brands including Carnival Cruise Line, Princess, Holland America, and Seabourn.
  2. 02The breach was part of ShinyHunters' massive 2026 campaign that hit over a dozen major U.S. corporations.

16Resolution

Carnival Corporation confirmed the breach and began notifying affected customers.

17Sources

Official documents

  • Carnival Corporation data breach notification

References

  1. [1]BleepingComputer: Carnival Cruise confirms data breach affecting nearly 6 million people
  2. [2]Have I Been Pwned - Carnival breach listing
Fact sheetEL-0392

Dates

Event
1 Apr 2026
Started
1 Apr 2026
Discovered
1 Apr 2026
Disclosed
28 May 2026
Ongoing
No

Target

Organisation
Carnival Corporation & plc
Type
Travel Company
Sector
Cruise / Hospitality
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through data extortion.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
7,500,000
Records
7,500,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Likely (standard for ShinyHunters)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.