Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Carnival Corporation Ltd.
bd_843aca7813130288 · schema v1 · pii pii-v1
Full breach record for Carnival Corporation Ltd. →Carnival Corporation reported a cybersecurity event where an unauthorized actor used social engineering to deceive an employee and gain access to a limited portion of the company's IT system on April 14, 2026. The actor illegally copied personal information, which was determined on April 22, 2026. The company blocked the activity, engaged third-party security experts, and is offering 24 months of complimentary credit monitoring to affected individuals.
California clockDiscovered Apr 14, 2026 → Notified May 27, 202643d ✗ CA 30-day late6 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_24671352cfb8e0c5Maine State AGfiled 2026-05-27Verified
- bd_403cc5ab7d096381Indiana State AGfiled 2026-05-27Verified
- bd_aa341ce145e41ff4Delaware State AGfiled 2026-05-27Verified
- bd_debade6bb3f0ccedNew Hampshire State AGfiled 2026-05-27Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_a217ec232607f2bdVermont State AGfiled 2026-05-28(1d gap)Verified
- bd_b40f7e0268a40f14South Carolina State AGfiled 2026-05-28(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624003
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 27, 2026
- Raw hash
- e6cb379e9d1ec163e390eef2b16ed93d5c9ead016792676149b50a5ad8555775
Reporting entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Victim entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Incident
- Discovered
- Apr 14, 2026
- Materiality determined
- —
- Notification sent
- May 27, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- CA 30-day late · 43dLeak >30dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 14, 2026→ Notified: May 27, 202643d 30 calendar days CA 30-day late California Consumers notified: May 27, 2026→ AG copy submitted: May 27, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.