
Social engineering attacks are scam methods used by “bad actors” to trick people into giving them sensitive information or access.
WASHINGTON — A recent data breach at Carnival Corporation may have exposed the personal information of nearly 6 million people.
The company said it is contacting individuals whose personal data may have been compromised in the recent cybersecurity incident.
Carnival declares violation Press release issued on May 27 It also said notification letters are being sent to anyone affected by the April 2026 incident.
The total number of people affected by the attack is estimated to be 5,995,277. Data Breach Notification on Maine Attorney General’s Website.
The breach occurred on April 10 and was discovered days later on April 14, the notice said.
Carnival said the company’s IT security systems discovered unauthorized activity involving employee accounts. The company determined that the account was compromised by social engineering, a method of tricking people into handing over security information or gaining access to an account.
Carnival said the hackers only accessed “limited parts” of the company’s IT systems.
The company said the investigation is ongoing, but the personal information believed to have been compromised includes the following:
- Name
- address
- telephone number
- date of birth
- A government-issued identification number, such as a driver’s license or passport number
Carnival said it will provide free credit monitoring services to U.S. individuals for two years through its preferred third-party provider, TransUnion.
Carnival pledged to take steps to “further secure its systems” and strengthen its security and monitoring controls.
We encourage potentially affected individuals to participate in free credit monitoring services and to report it to local police if they believe they have been a victim of identity theft or fraud.


