---
title: "Carnival Corporation social-engineering data incident"
description: "Evidence-backed account of Carnival Corporation social-engineering data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/carnival-corporation-social-engineering-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/carnival-corporation-social-engineering-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/carnival-corporation-social-engineering-data-incident-2026/stix.json"
---

# Carnival Corporation social-engineering data incident

An unauthorized actor used social engineering against an employee account, accessed part of Carnival's IT environment, and copied personal information. Carnival confirmed copied identity and contact information; HIBP separately characterized additional data classes and a incident corpus.

Last modified Aug 9, 2026 · 4 sources

## Summary

- **Environment:** Carnival's characterization of system-access scope.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

An unauthorized actor used social engineering against an employee account, accessed part of [Carnival Corporation](https://www.carnivalcorp.com/)'s IT environment, and copied personal information. [3](#source-3)

## Impact

Carnival confirmed copied identity and contact information; HIBP separately characterized additional data classes and a incident corpus. [3](#source-3)

Documented data types include:

- Contact information — Carnival listed addresses, email addresses, and phone numbers; affected fields varied by individual. [3](#source-3) [4](#source-4)
- Passport numbers — Carnival listed passport numbers as an example of impacted government-issued identification; affected fields varied by individual. [3](#source-3) [4](#source-4)
- Names — Names were listed by Carnival and also appear in HIBP's corpus data classes; affected fields varied by individual. [3](#source-3) [4](#source-4)
- Dates of birth — Dates of birth were listed by Carnival and also appear in HIBP's corpus data classes; affected fields varied by individual. [3](#source-3) [4](#source-4)
- Loyalty program information — Loyalty-program details listed for records in HIBP's incident corpus; Carnival's May 27 notice does not name a loyalty program. [3](#source-3) [4](#source-4)
- Driver's license numbers — Carnival listed driver's license numbers as an example of impacted government-issued identification; affected fields varied by individual. [3](#source-3) [4](#source-4)
- Gender information — Gender information listed for records in HIBP's incident corpus; Carnival's May 27 notice does not list gender. [3](#source-3) [4](#source-4)
- Geographic location information — Geographic locations listed for records in HIBP's incident corpus; Carnival's notice separately lists postal addresses. [3](#source-3) [4](#source-4)

A cited record reports 6,000,000 individuals (Texas Attorney General estimate published June 22, 2026; distinct from the exact Texas-consumer count and HIBP corpus count; as of 2026-06-22). [1](#source-1) [3](#source-3) [4](#source-4)

A cited record reports 800,060 individuals (Texas consumers reported in Carnival's data-incident notification submitted to the Texas Attorney General; as of 2026-06-22). [1](#source-1) [3](#source-3) [4](#source-4)

A cited record reports 7,531,359 records (Unique email addresses represented in HIBP's incident corpus; not a Carnival-confirmed affected-person count or a total source-row count; as of 2026-04-24). [1](#source-1) [3](#source-3) [4](#source-4)

Carnival began notifying individuals whose personal information was affected, using email where required and available. [3](#source-3)

## Timeline

### April 14, 2026 — Documented event

Carnival's notice and its SEC filing identify April 14 as the incident date; HIBP separately lists April 18 as its BreachDate. [2](#source-2) [3](#source-3) [4](#source-4)

### April 14, 2026 — Documented activity ended

Carnival said it stopped the attack on April 14 and was not aware of unauthorized activity after that point. [3](#source-3)

### April 14, 2026 — Discovery

Date Carnival says its IT security team identified unauthorized activity involving an employee account. [3](#source-3)

### May 27, 2026 — Public disclosure

Date Carnival says individual notifications began and the substitute notice was issued. [3](#source-3)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

An unauthorized actor used social engineering to deceive an employee and obtain access through the employee's account. [3](#source-3)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Six purported class actions were brought in April 2026 in the U.S. District Court for the Southern District of Florida in relation to the April 14 incident. On April 22, Carnival first determined that the unauthorized actor had illegally copied personal information. The unauthorized actor gained access to a limited portion of Carnival's IT system. Carnival engaged third-party security experts and enhanced its security and monitoring controls. The Texas Attorney General announced an ongoing investigation, following a Civil Investigative Demand, into whether Carnival adequately safeguarded Texas consumers' information and maintained reasonable protective procedures. Carnival offered eligible U.S. individuals two years of complimentary TransUnion credit monitoring. In May 2026, the district court granted the plaintiffs' motion to consolidate the matters. Carnival notified law enforcement. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2) [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/carnival-corporation-social-engineering-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach That Compromised Personal Information of Over 6 Million People

regulatory · Office of the Attorney General of Texas

<https://oag.state.tx.us/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach>

<a id="source-2"></a>

### Carnival Corporation Ltd. Quarterly Report on Form 10-Q for the quarter ended May 31, 2026

regulatory · U.S. Securities and Exchange Commission

<https://www.sec.gov/Archives/edgar/data/815097/000081509726000096/ccl-20260531.htm>

<a id="source-3"></a>

### Carnival Corporation Notice of Data Breach

official · Carnival Corporation

<https://www.carnivalcorp.com/wp-content/uploads/2026/05/Website-Notice-Substitute-Notice-05.27.26.pdf>

<a id="source-4"></a>

### Carnival breach record

advisory · Have I Been Pwned · Apr 24, 2026

<https://haveibeenpwned.com/api/v3/breach/Carnival>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: Texas Attorney General Carnival investigation
2. **Resulted In · 100% confidence · current**  
   Carnival data-security class actions: Six purported class actions were brought in April 2026 in the U.S. District Court for the Southern District of Florida in relation to the April 14 incident.
3. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: On April 22, Carnival first determined that the unauthorized actor had illegally copied personal information.
4. **Exposed Data Category · 100% confidence · current**  
   Carnival Corporation personal-information exposure: Contact information
5. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: The unauthorized actor gained access to a limited portion of Carnival's IT system.
6. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: May 2026 Carnival Corporation breach notification
7. **Affected Individual Count · 100% confidence · current**  
   Carnival Corporation personal-information exposure: 6,000,000 individual
8. **Exposed Data Category · 100% confidence · current**  
   Carnival Corporation personal-information exposure: Passport numbers
9. **Exposed Data Category · 100% confidence · current**  
   Carnival Corporation personal-information exposure: Names
10. **Affected Individual Count · 100% confidence · current**  
   Carnival Corporation personal-information exposure: 800,060 individual
11. **Exposed Data Category · 100% confidence · current**  
   Carnival Corporation personal-information exposure: Dates of birth
12. **Occurred At · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: 2026-04-14
13. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: Carnival Corporation personal-information exposure
14. **Exposed Data Category · 90% confidence · current**  
   Carnival Corporation personal-information exposure: Loyalty program information
15. **Disclosed At · 100% confidence · current**  
   May 2026 Carnival Corporation breach notification: 2026-05-27
16. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: Carnival engaged third-party security experts and enhanced its security and monitoring controls.
17. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: Carnival data-security class actions
18. **Resulted In · 100% confidence · current**  
   Texas Attorney General Carnival investigation: The Texas Attorney General announced an ongoing investigation, following a Civil Investigative Demand, into whether Carnival adequately safeguarded Texas consumers' information and maintained reasonable protective procedures.
19. **Ended At · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: 2026-04-14
20. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: An unauthorized actor used social engineering to deceive an employee and obtain access through the employee's account.
21. **Resulted In · 100% confidence · current**  
   May 2026 Carnival Corporation breach notification: Carnival began notifying individuals whose personal information was affected, using email where required and available.
22. **Resulted In · 100% confidence · current**  
   May 2026 Carnival Corporation breach notification: Carnival offered eligible U.S. individuals two years of complimentary TransUnion credit monitoring.
23. **Exposed Data Category · 100% confidence · current**  
   Carnival Corporation personal-information exposure: Driver's license numbers
24. **Exposed Data Category · 90% confidence · current**  
   Carnival Corporation personal-information exposure: Gender information
25. **Exposed Data Category · 90% confidence · current**  
   Carnival Corporation personal-information exposure: Geographic location information
26. **Resulted In · 100% confidence · current**  
   Carnival data-security class actions: In May 2026, the district court granted the plaintiffs' motion to consolidate the matters.
27. **Resulted In · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: Carnival notified law enforcement.
28. **Exposed Record Count · 100% confidence · current**  
   Carnival Corporation personal-information exposure: 7,531,359 record
29. **Affected Organization · 100% confidence · current**  
   Carnival Corporation personal-information exposure: Carnival Corporation
30. **Discovered At · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: 2026-04-14
31. **Affected Organization · 100% confidence · current**  
   April 2026 Carnival Corporation social-engineering incident: Carnival Corporation

</details>
