What happened
Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.
How the deception worked
Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.
Sources (3)
- Carnival Cruise confirms data breach affecting nearly 6 million peopleBleepingComputer·bleepingcomputer.comOpen ↗
- Carnival Data Breach Exposed 6 Million PeopleSecurityWeek·securityweek.comOpen ↗
- Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data BreachOffice of the Texas Attorney General·texasattorneygeneral.govOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.