01Summary
In April 2026, ShinyHunters gained unauthorized access to Carnival Corporation's systems and exfiltrated customer data. The stolen records included personal information from the company's loyalty programs and booking systems. Carnival confirmed the breach in late May 2026 and the data was subsequently listed on Have I Been Pwned with 7.5 million affected accounts. The breach was part of ShinyHunters' broader 2026 campaign targeting major U.S. travel, telecommunications, and healthcare companies.
02Background
Carnival Corporation is the world's largest cruise company, operating a fleet of nearly 100 ships across multiple brands. Its customer databases contain extensive personal information including passport details, frequent cruiser numbers, and payment information, making it a high-value target for cybercriminal extortion groups.
03Key revelations
- 01Scale of customer data held by major cruise lines across multiple brands.
- 02Continued success of ShinyHunters' extortion campaign against major U.S. corporations in 2026.
04Technical analysis
The attack followed ShinyHunters' established methodology, likely involving social engineering (vishing) to compromise employee credentials and gain access to internal customer databases for bulk data exfiltration.
- Attack vector
- Social engineering / Credential compromise
- Attack method
- Data exfiltration and extortion
- Initial access
- Social engineering (likely vishing)
- Exfiltration
- Bulk data extraction
05Threat actor
ShinyHunters is a prolific cybercriminal/extortion group known for targeting large corporations and high-value datasets for financial gain through data extortion.
Aliases
- SH
- Scattered LAPSUS$ Hunters
Attribution sources
- ShinyHunters leak site
- Carnival Corporation SEC filing
- BleepingComputer
- Have I Been Pwned
06Victims and impact
Countries affected
- United States
- Global
07Data exposed
Data types
- PII
- Names
- Email addresses
- Phone numbers
- Loyalty program data
- Booking information
08Financial damage
Reputational damage, regulatory fines, and potential class-action lawsuits.
09Timeline
- 2026-04-01Approximate date of initial breach.
- 2026-05-28Carnival confirms breach; data listed on Have I Been Pwned (7.5M records).
10Reaction and fallout
Public reaction
Concern among cruise passengers over exposure of personal travel data and loyalty program details.
11Legal
Ongoing investigations; class-action lawsuits anticipated.
Civil lawsuits
- Anticipated class-action lawsuits
12Significance and legacy
Significance
One of the largest breaches in the cruise and hospitality industry, affecting customers across multiple major cruise brands globally.
Legacy
Highlights the vulnerability of the travel and hospitality sector to data extortion attacks.
13Disclosure and media
- Authentication
- ShinyHunters leak site and Carnival Corporation SEC filing
Publishing organisations
- BleepingComputer
- Have I Been Pwned
- Reuters
15Field notes
- 01Carnival operates nearly 100 cruise ships across brands including Carnival Cruise Line, Princess, Holland America, and Seabourn.
- 02The breach was part of ShinyHunters' massive 2026 campaign that hit over a dozen major U.S. corporations.
16Resolution
Carnival Corporation confirmed the breach and began notifying affected customers.
17Sources
Official documents
- Carnival Corporation data breach notification
References
- [1]BleepingComputer: Carnival Cruise confirms data breach affecting nearly 6 million people
- [2]Have I Been Pwned - Carnival breach listing









