Carnival Corporation, the world’s largest cruise line operator, has confirmed a massive data breach affecting nearly 6 million individuals. Notification letters began going out in late May 2026 after an investigation revealed that attackers gained unauthorized access to an employee’s account through a social engineering attack on April 14, 2026.
The compromised data includes names, addresses, dates of birth, email addresses, phone numbers, and government-issued identification numbers such as driver’s license and passport numbers. The ShinyHunters extortion group claimed responsibility in April, stating they stole 8.7 million records from Carnival’s systems. An analysis by HaveIBeenPwned suggested approximately 7.5 million accounts related to the Holland America Mariner Society loyalty program may have been affected. Carnival has notified the Maine Attorney General’s Office that 5,995,277 people were impacted and is offering 24 months of free credit monitoring.
Source
Coverage from BleepingComputer, SecurityWeek, and The Record.
Commentary
Social engineering continues to be the skeleton key that bypasses even well-funded organizations’ technical controls. The fact that a single compromised employee account led to the exfiltration of nearly 6 million records speaks to insufficient internal segmentation and monitoring. If it takes weeks to detect unauthorized access from a phished account, your detection pipeline needs serious attention.
ShinyHunters has been on an absolute tear in 2026, and organizations relying on perimeter defenses while neglecting identity and access management are easy prey. If you were a Holland America loyalty member, assume your data is out there and act accordingly.
