AI Stories on SHORT INFO are generated & curated with AI
unverified 16 Jun, 14:05

Carnival confirms 5,995,277 affected by April phishing breach; ShinyHunters listed data on leak portal

Anyone in Carnival $CCL loyalty programs (Mariner Society, Holland America) may have had personal data exposed. Carnival confirmed 5,995,277 affected after an April phishing attack on an employee account. ShinyHunters listed the data on its leak portal April 18; notifications beg

Anyone enrolled in Carnival Corporation $CCL loyalty programs, including the Mariner Society and Holland America Line memberships, may have had personal data exposed. Carnival confirmed on May 28 that 5,995,277 individuals were affected by a breach that began with a social engineering attack on April 14, 2026. An employee was deceived into providing access to a limited portion of Carnival's IT systems, and the unauthorized actor copied personal data before being blocked on April 22. The ShinyHunters hacking group listed Carnival on its pay-or-leak portal on April 18, claiming 8.7 million records with 7.5 million unique email addresses had been stolen. According to the breach notice filed with Maine's Attorney General, exposed information includes names, dates of birth, genders, email addresses, physical addresses, government-issued identification numbers, and loyalty program status. Notifications began on May 27, 2026. Eligible US residents are being offered two years of complimentary credit monitoring through TransUnion. Carnival stated it has implemented additional security and monitoring controls following the incident. Source: Help Net Security / BleepingComputer, citing the Maine Attorney General filing and Have I Been Pwned.

Published on
ThreadsBlueskyFacebookX