Large white cruise ship docked at port against a blue sky
Photo via Unsplash

TL;DR: ShinyHunters claims to have stolen 8.7 million records from Carnival Corporation, the company behind Carnival Cruise Line, Princess Cruises, and Holland America Line. The breach came through a phishing attack on a single employee account. ShinyHunters posted Carnival on their "pay or leak" portal on April 18 with a deadline of April 21. Carnival confirmed the breach but hasn't said what data was taken. This is at least Carnival's fifth known cybersecurity incident since 2019. New York already fined them $5 million for the last round. At some point, "we take security seriously" stops being a statement and starts being a punchline.

One Phishing Email. 8.7 Million Records. Again.

On April 18, 2026, ShinyHunters listed Carnival Corporation on their dark web extortion portal. The claim: 8.7 million records containing personally identifiable information and internal corporate data. The threat: pay up by April 21 or watch it go public [1].

Their exact message, posted alongside half a dozen other companies: "This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way" [2].

Carnival confirmed the breach. In a statement, the company said it "acted quickly to block unauthorized activity following a phishing incident involving a single user account" and that it had engaged "top global security experts" to assess the scope [1].

A single user account. That's all it took. One employee clicked the wrong link, and ShinyHunters walked away with what they claim is 8.7 million records from a company that operates nine cruise brands across 95 ships.

What Was Stolen

Carnival hasn't confirmed what data was accessed. ShinyHunters says it's 8.7 million records of PII plus internal corporate documents. Given ShinyHunters' track record, that likely means some combination of:

  • Full names and contact details
  • Booking and travel history
  • Payment information (partial or full)
  • Passport and identity documents (cruises require them)
  • Internal corporate files

Carnival hasn't independently verified the volume or sensitivity of what was taken. That silence tells you something. When companies can say "no sensitive data was accessed," they say it fast. When they can't, you get "we're still investigating."

If you've booked a Carnival, Princess, or Holland America cruise in recent years, your data may be in play. Carnival Corporation also owns Costa Cruises, Cunard, AIDA Cruises, P&O Cruises, and Seabourn. That's a lot of passengers.

Carnival's Greatest Hits: A Breach Timeline

This isn't Carnival's first rodeo. It's not their second. It might not even be their fifth. Here's the highlight reel:

  • May 2019: Attackers accessed 124 employee email accounts on Office 365 through phishing and brute force. Carnival's security team first suspected the breach in May 2019 [3].
  • March 2020: Another data breach exposing customer and employee information.
  • August 2020: Ransomware attack encrypting systems and accessing data.
  • December 2020: Malware attack hitting Costa Cruises systems on Christmas Day.
  • January 2021: Yet another ransomware attack.
  • March 2021: Phishing attack hitting Carnival, Holland, and Princess cruise lines.
  • April 2026: ShinyHunters gets in through (you guessed it) phishing.

Four incidents in two years got them a $5 million fine from New York's Department of Financial Services [3]. The DFS found Carnival had failed to implement multifactor authentication, took 10 months to report the first incident, and failed to conduct adequate employee security training.

They also settled with 45 state attorneys general for $1.25 million after the earlier breaches affected 180,000 customers and employees [3].

So in 2026, after all of that, all the fines, all the settlements, all the promises to do better, a single phishing email still took them down.

The April 21 Hit List

Carnival is one of eight companies ShinyHunters posted with today's deadline. The full list, all posted within days of each other [2]:

Carnival Corporation

8.7 million records via phishing. Breach confirmed by the company.

Canada Life Assurance

5.6 million Salesforce records. Up to 70,000 customers affected.

Zara

Linked to the Anodot-Snowflake breach wave. Same supply chain that hit Rockstar Games.

7-Eleven

Part of ShinyHunters' Salesforce-focused campaign. Scope unconfirmed.

Medtronic & Pitney Bowes

Medical devices and shipping tech. Also on the April 21 list. No confirmation yet.

This is how ShinyHunters operates now. Batch processing. They breach companies in waves (usually through common infrastructure like Salesforce, Snowflake, or Okta) then post them all at once with synchronized deadlines. It's extortion at scale.

Why Cruise Line Data Is a Goldmine

Cruise companies sit on an unusually complete picture of their customers. To book a cruise, you hand over:

  • Full legal name (as it appears on your passport)
  • Passport number and expiration date
  • Date of birth
  • Home address
  • Payment card details
  • Emergency contact information
  • Travel companions' details
  • Dietary and medical requirements

That's not a mailing list. That's an identity theft starter kit. Paired with booking history, attackers know when you traveled, where you went, and who you went with. That kind of detail makes phishing attempts extremely convincing. "Hi, I'm calling about your Princess Cruise to the Mediterranean last September. We noticed an issue with your booking..." You'd take that call.

The Eurail breach earlier this month exposed passport numbers for 308,000 travelers. Carnival's breach could be an order of magnitude worse.

What to Do If You've Cruised With Carnival

Assume Your Data Was Included

If you've booked with Carnival, Princess, Holland America, Costa, Cunard, AIDA, P&O, or Seabourn, treat this as if your data was compromised until told otherwise.

Watch for Cruise-Themed Phishing

ShinyHunters' data enables targeted scams. Any email about booking changes, refunds, or loyalty points should be verified by logging into your account directly, not through a link in the message.

Check Your Passport

If passport data was in the breach, you may want to consider reporting a compromised passport to the State Department. At minimum, monitor for unauthorized use of your passport number.

Freeze Your Credit

With name, DOB, and address potentially exposed, a credit freeze is your best defense. Equifax (1-888-298-0045), Experian (1-888-397-3742), TransUnion (1-888-909-8872). Free. Takes five minutes per bureau.

The Real Question

How many times does a company get breached before regulators step in with more than a fine? Carnival has been hacked repeatedly since 2019. They paid $5 million to New York. They settled with 45 states. They promised to improve. And then they got taken out by phishing. Again.

At what point does a fine stop being a penalty and start being a cost of doing business? $5 million is what Carnival makes in about 20 minutes of revenue. If the punishment doesn't change the behavior, the punishment isn't working.

Meanwhile, ShinyHunters is adding companies to their leak portal faster than security teams can respond. They've hit 100+ companies via SSO campaigns, 400+ via Salesforce, and they're not slowing down. If your company's security plan is "hope they don't pick us," that's not a plan. That's a prayer.

References

  1. Cyber Insider - Carnival Corporation probes data breach after claims of 8.7M records theft (April 2026)
  2. Cybernews - ShinyHunters adds Zara, Carnival, 7-Eleven to growing ransomware leak list (April 2026)
  3. HALOCK - Carnival Cruises Into Rough Waters: Data Breaches
  4. BleepingComputer - Carnival Cruise hit by data breach, warns of data misuse risk
  5. Cybersecurity Dive - Carnival to pay $5M for cyber violations to NY financial regulator