news.mlab.sh
Back to the feed
data-breach

Carnival Cruise confirms data breach affecting nearly 6 million people

High
Summary

Carnival Corporation confirmed a data breach impacting nearly 6 million individuals, attributed to the ShinyHunters extortion gang. The breach occurred through a social engineering attack targeting an employee’s account, resulting in the theft of personal information including names, dates of birth, and loyalty program details. This incident follows previous breaches and highlights the ongoing threat landscape for large organizations.

The data breach, initially discovered on April 14, 2026, stemmed from an employee falling victim to a social engineering attack, allowing unauthorized access to a portion of Carnival’s IT systems. The ShinyHunters group subsequently exploited this access, stealing over 8.7 million records containing personally identifiable information and substantial internal corporate data. The company’s rapid response included blocking the activity and engaging third-party security experts to investigate and strengthen security protocols. This incident underscores the vulnerability of organizations relying on employee access and the effectiveness of social engineering tactics.

Read the full article at BleepingComputer