{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"},"incident":{"slug":"2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi","title":"Carnival confirms social engineering of an employee account exposed 6 million customers","date":"2026-04-14","date_precision":"day","year":2026,"victim_org":"Carnival Corporation","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5995277,"threat_actor":"ShinyHunters","summary":"Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.","how_it_worked":"Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.","lessons":"Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.","confidence":"Reported","sources":[{"title":"Carnival Cruise confirms data breach affecting nearly 6 million people","url":"https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/","publisher":"BleepingComputer"},{"title":"Carnival Data Breach Exposed 6 Million People","url":"https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/","publisher":"SecurityWeek"},{"title":"Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach","url":"https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach","publisher":"Office of the Texas Attorney General"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"}}