Carnival Corporation Ltd.
ent_019e2300e790ac082b3b398e8a7dfe43
Disclosures
25+
State AG · Leak Site · 14 jurisdictions
Incidents
4
filings grouped by incident
Max affected reported
6,000,000
nationwide · State AG DE
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Carnival Corporation Ltd.
- Normalized
- carnival— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- F1OF2ZSX47CR0BCWA982
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- carnivalcorp.com
Disclosure history (newest 25)newest first
- ⭐Texas State AGas victim2026-05-28
Carnival Corporation based in Miami, Florida, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-14 and reported on 2026-05-28. 800,060 Texas residents were affected. 5,995,277 individuals affected in total. Types of information involved: Name of individual;Address;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Date of Birth. Consumers were notified via Notice by publication in print media;Posted at company website or special website;Email.
- 🍁Vermont State AGas victim2026-05-28
Carnival Corporation reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-28. The reporting organization type is Hospitality. 3,915 Vermont residents were affected. Categories of data breached: Government ID Numbers.
- 🌴South Carolina State AGas victim2026-05-28
Carnival Corporation notified South Carolina residents of a cybersecurity event on May 27, 2026. On April 14, 2026, unauthorized activity involving an employee's account was identified. An unauthorized actor used social engineering to gain access to a limited portion of the Company's IT system. The Company blocked the activity and engaged third-party security experts. Personal information was illegally copied starting April 22, 2026. The Company is offering 24 months of complimentary credit monitoring through TransUnion.
- 🌲Washington State AGas victim2026-05-27
Carnival Corporation, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2026-04-14 and filed notice on 2026-05-27. 54,960 Washington residents were affected. 43 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2026-05-27
Carnival Corporation reported a data breach occurring on April 10, 2026, discovered on April 14, 2026. The incident affected 5,995,277 individuals nationwide, including 9,746 Maine residents. Notification was sent electronically on May 27, 2026. Affected individuals were offered 24 months of credit monitoring and fraud assistance through TransUnion. The specific nature of the breach and data types were not detailed in the filing.
- 🏎️Indiana State AGas victim2026-05-27
Carnival Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2026-04-10 and was reported on 2026-05-27. 85,084 Indiana residents were affected. 5,995,277 individuals affected in total.
- 🦫Oregon State AGas victim2026-05-27
Carnival Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2026-05-27. The breach occurred during 4/10/2026 - 4/14/2026. The breach was discovered on 4/14/2026. 5,995,277 individuals were affected. Notice was sent on 5/27/2026.
- 🐻California State AGas victim2026-05-27
Carnival Corporation reported a cybersecurity event where an unauthorized actor used social engineering to deceive an employee and gain access to a limited portion of the company's IT system on April 14, 2026. The actor illegally copied personal information, which was determined on April 22, 2026. The company blocked the activity, engaged third-party security experts, and is offering 24 months of complimentary credit monitoring to affected individuals.
- 💎Delaware State AGas victim2026-05-27
Carnival Corporation notified affected individuals of a cybersecurity event where an unauthorized actor used social engineering to gain access to an employee's account and illegally copied personal information. The incident was discovered on April 14, 2026, and the company offered 24 months of complimentary credit monitoring through TransUnion.
- 🌽Iowa State AGas victim2026-05-27
Carnival Corporation, a hospitality sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2026-05-27.
- ⛰️New Hampshire State AGas victim2026-05-27
Carnival Corporation notified New Hampshire AG of a cybersecurity event where an unauthorized actor used voice phishing (vishing) to obtain employee credentials and exfiltrate personal information of approximately 11,477 NH residents. The incident involved names, addresses, emails, phone numbers, DOB, and government IDs. Notifications began May 27, 2026, offering 24 months of credit monitoring.
- 🏛️Massachusetts State AGas victim2026-05-01
Carnival Corporation notified Massachusetts residents of a cybersecurity event on May 27, 2026. On April 14, 2026, an unauthorized actor used social engineering/phishing to gain access to an employee account and copy personal information. The company blocked the activity, engaged third-party security experts, and is offering 24 months of complimentary TransUnion credit monitoring. The specific data elements are redacted in this template but include PII.
- GLOBALLeak Siteas victim2026-04-18
Over 8.7M records containing PII and other terabytes of internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
- 💎Delaware State AGas victim2021-12-04
Carnival Corporation notified Delaware AG of unauthorized third-party access to IT systems detected on August 15, 2020. Access occurred in early August 2020, impacting guest, employee, and crew data including names, addresses, passport numbers, DOB, and potentially SSN/health info. Company engaged cybersecurity firm, notified law enforcement, and offers 12 months credit monitoring.
- 🐻California State AGas victim2021-10-18
Carnival Corporation and plc submitted a data security breach notification to the California Office of the Attorney General on March 12, 2021. The incident involved unauthorized access to customer data, potentially exposing names, Social Security numbers, and financial account information. The company provided one year of free credit monitoring, cyber monitoring, and a $1,000,000 insurance reimbursement policy to affected individuals. The notification covers residents of multiple US states, including California, Iowa, and Kentucky.
- 🦫Oregon State AGas victim2021-10-18
Carnival Corporation and plc reported a data breach to the Oregon Attorney General. The breach was reported on 2021-10-18. The breach occurred during 3/12/2021. The breach was discovered on 3/19/2021. 20,992 individuals were affected. Notice was sent on 5/21/2021.
- 🦞Maine State AGas victim2021-10-16
Carnival Corporation and plc reported a data breach impacting 94 Maine residents, which was discovered on March 19, 2021. The incident, which occurred on March 12, 2021, was described as an external system breach or hacking. The company provided written notification to affected individuals on May 21, 2021, and offered one year of complimentary credit monitoring services.
- 🦬Montana State AGas victim2021-10-06
Carnival Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2021-10-06. The breach occurred on 4/8/2021. 63 Montana residents were affected.
- 🦬Montana State AGas victim2021-05-21
Carnival Corporation & PLC reported a data breach to the Montana Attorney General. The breach was reported on 2021-05-21. The breach occurred on 3/19/2021. 44 Montana residents were affected.
- 🐻California State AGas victim2021-02-04
Carnival Corporation and plc disclosed a cybersecurity incident affecting US adult guests. Unauthorized third-party access to IT systems was detected on August 15, 2020. The breach impacted names, addresses, phone numbers, passport numbers, dates of birth, and in some cases, SSNs and health information. The company engaged a cybersecurity firm, notified law enforcement, and offered 12 months of credit monitoring.
- 🦫Oregon State AGas victim2020-10-16
Carnival Corporation and plc reported a data breach to the Oregon Attorney General. The breach was reported on 2020-10-16. 37,500 individuals were affected.
- 🦞Maine State AGas victim2020-10-16
Carnival Corporation and plc reported a data breach affecting approximately 37,500 individuals, including 8 Maine residents. The breach, described as an external system breach (hacking), occurred on August 4, 2020, and was discovered on September 29, 2020. The company began notifying affected individuals on October 13, 2020, and will offer complimentary credit monitoring services.
- 🐻California State AGas victim2020-10-13
Carnival Corporation and plc reported unauthorized third-party access to IT systems in August 2020. The breach impacted guests, employees, and crew, potentially exposing names, addresses, passport numbers, DOBs, and possibly SSNs and health info. The company engaged cybersecurity investigators, notified law enforcement, and offered credit monitoring. Investigation was ongoing at the time of the October 2020 substitute notice.
- 💎Delaware State AGas victim2020-10-13
Carnival Corporation and plc notified the Delaware Attorney General of a cybersecurity incident occurring between April 11 and July 23, 2019. The company identified suspicious activity on May 31, 2019, leading to an investigation that revealed unauthorized access by an unsanctioned third party. The breach affected approximately 6 million individuals nationwide, including roughly 10,000 Delaware residents. Affected data included names, addresses, phone numbers, email addresses, and, for some, Social Security numbers and credit card information. Carnival engaged forensic experts and offered complimentary credit monitoring.
- 🌴South Carolina State AGas victim2020-03-06
South Carolina Attorney General's office received a breach notification from Carnival Corporation & PLC in 2020. The provided PDF document contains only page markers and no substantive text regarding the incident details, victims, or response actions.