Carnival Corporation social-engineering data incident

An unauthorized actor used social engineering against an employee account, accessed part of Carnival's IT environment, and copied personal information. Carnival confirmed copied identity and contact information; HIBP separately characterized additional data classes and a incident corpus.

Last modified

Summary

  • Environment: Carnival's characterization of system-access scope.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

An unauthorized actor used social engineering against an employee account, accessed part of Carnival Corporation’s IT environment, and copied personal information. [3]

Impact

Carnival confirmed copied identity and contact information; HIBP separately characterized additional data classes and a incident corpus. [3]

Documented data types include:

  • Contact information — Carnival listed addresses, email addresses, and phone numbers; affected fields varied by individual. [3][4]
  • Passport numbers — Carnival listed passport numbers as an example of impacted government-issued identification; affected fields varied by individual. [3][4]
  • Names — Names were listed by Carnival and also appear in HIBP’s corpus data classes; affected fields varied by individual. [3][4]
  • Dates of birth — Dates of birth were listed by Carnival and also appear in HIBP’s corpus data classes; affected fields varied by individual. [3][4]
  • Loyalty program information — Loyalty-program details listed for records in HIBP’s incident corpus; Carnival’s May 27 notice does not name a loyalty program. [3][4]
  • Driver’s license numbers — Carnival listed driver’s license numbers as an example of impacted government-issued identification; affected fields varied by individual. [3][4]
  • Gender information — Gender information listed for records in HIBP’s incident corpus; Carnival’s May 27 notice does not list gender. [3][4]
  • Geographic location information — Geographic locations listed for records in HIBP’s incident corpus; Carnival’s notice separately lists postal addresses. [3][4]

A cited record reports 6,000,000 individuals (Texas Attorney General estimate published June 22, 2026; distinct from the exact Texas-consumer count and HIBP corpus count; as of 2026-06-22). [1][3][4]

A cited record reports 800,060 individuals (Texas consumers reported in Carnival’s data-incident notification submitted to the Texas Attorney General; as of 2026-06-22). [1][3][4]

A cited record reports 7,531,359 records (Unique email addresses represented in HIBP’s incident corpus; not a Carnival-confirmed affected-person count or a total source-row count; as of 2026-04-24). [1][3][4]

Carnival began notifying individuals whose personal information was affected, using email where required and available. [3]

Timeline

  1. Documented event

    Carnival’s notice and its SEC filing identify April 14 as the incident date; HIBP separately lists April 18 as its BreachDate.

    [2][3][4]
  2. Documented activity ended

    Carnival said it stopped the attack on April 14 and was not aware of unauthorized activity after that point.

    [3]
  3. Discovery

    Date Carnival says its IT security team identified unauthorized activity involving an employee account.

    [3]
  4. Public disclosure

    Date Carnival says individual notifications began and the substitute notice was issued.

    [3]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

An unauthorized actor used social engineering to deceive an employee and obtain access through the employee’s account. [3]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Six purported class actions were brought in April 2026 in the U.S. District Court for the Southern District of Florida in relation to the April 14 incident. On April 22, Carnival first determined that the unauthorized actor had illegally copied personal information. The unauthorized actor gained access to a limited portion of Carnival’s IT system. Carnival engaged third-party security experts and enhanced its security and monitoring controls. The Texas Attorney General announced an ongoing investigation, following a Civil Investigative Demand, into whether Carnival adequately safeguarded Texas consumers’ information and maintained reasonable protective procedures. Carnival offered eligible U.S. individuals two years of complimentary TransUnion credit monitoring. In May 2026, the district court granted the plaintiffs’ motion to consolidate the matters. Carnival notified law enforcement. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2][3]