Social EngineeringPhishingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Carnival Corporation Ltd.
bd_2fa8add804519bbe · schema v1 · pii pii-v1
Full breach record for Carnival Corporation Ltd. →Carnival Corporation notified Massachusetts residents of a cybersecurity event on May 27, 2026. On April 14, 2026, an unauthorized actor used social engineering/phishing to gain access to an employee account and copy personal information. The company blocked the activity, engaged third-party security experts, and is offering 24 months of complimentary TransUnion credit monitoring. The specific data elements are redacted in this template but include PII.
Massachusetts clock✓ MA AG ≤30d17 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0bf5f8d0b505a1b8Leak Siteshinyhuntersfiled 2026-04-18(13d gap)Candidate
Regulatory filings (4) · sorted by filing gap
- bd_06ca13775dc757a3Washington State AGfiled 2026-05-27(26d gap)Verified by operator
- bd_6d8af3869b6bca55Oregon State AGfiled 2026-05-27(26d gap)Verified by operator
- bd_bb55a8f7f97eb1fbIowa State AGfiled 2026-05-27(26d gap)Verified by operator
- bd_104c3479219b55d2Texas State AGfiled 2026-05-28(27d gap)Verified by operator
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-857-carnival-corporation/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 406f01e09091a42b33e5d57ffcc8b95a515e0f8491623303c1ca7036b3d90216
Reporting entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Victim entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Incident
- Discovered
- Apr 14, 2026
- Materiality determined
- —
- Notification sent
- May 27, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.