Skip to main content
Back to overview
High

Carnival Corporation Confirms Data Breach Affecting Nearly 6 Million Individuals

Carnival Corporation, one of the world's largest cruise operators, confirmed a data breach on May 28, 2026, weeks after the ShinyHunters hacking group claimed to have stolen millions of customer records.

Key points

  • Phishing incident in April 2026 compromised an employee account.
  • ShinyHunters hacking group claimed responsibility for the data theft.
  • Nearly 6 million individuals affected.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social, Hacking activity

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
May 28, 2026
Updated
Jul 2, 2026
Confidence
High
Evidence
15 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social, Hacking activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

CarnivalcorpData DisclosureCarnival Corporation Confirms Data BreachAffecting NearlyMillion Individuals Carnival CorporationShinyHuntersNotificationsPhishingNearly

Quick context

Questions about this signal

What happened in this signal?

Carnival Corporation, one of the world's largest cruise operators, confirmed a data breach on May 28, 2026, weeks after the ShinyHunters hacking group claimed to have stolen millions of customer records. The incident originated from a phishing attack in April 2026 that compromised an employee's account, granting unauthorized access to a limited portion of the company's IT system. Notifications to affected individuals began on May 27, 2026.

When was this signal reported?

Shadow Tier lists May 28, 2026 as the signal date.

Which organization is connected to this signal?

Carnivalcorp is the organization connected to this public signal.

Explore Carnivalcorp
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence