Confirmed breach. Intrusion Apr 10, 2026–Apr 14, 2026, discovered Apr 14, 2026 — the first regulatory filing landed 17 days later (flagged late). 6,850,297 individuals reported across the linked filings.
incident inc_d2452afe131348e3 · merge_method human · confidence 100%
Litigation Timing
Notification delay
17days
Discovered → first regulatory filing
Discovery variance
0days
Range of discovered_at dates across filings
Leak precedence
Regulatory clocksTexas✗ TX AG >30dWashington⏱ WA AG >30dLeak gap⏱ Leak >30dMassachusetts✓ MA AG ≤30dFull clock table in Litigation Timeline
Leak SiteState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedshinyhunters
13days
Gap between first leak claim and first regulatory filing
Filing span
40days
Time between earliest and latest filing
Not recorded for this incident
Materiality delta · SEC filing delay — no SEC 8-K in this cluster.
Affected (total reported)
6,850,297
Data types
—
Jurisdictions
6
IA MA OR TX WA
Linked filings
6
Leak Site · State AG
Affected residents by state
per-filing reported counts
OR5,995,277
TX800,060
WA54,960
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Apr 10, 2026 → Apr 14, 2026
When the intrusion reportedly occurred, per the linked filings
Breach discoveredAG web form
Apr 14, 2026
Reported by MASSACHUSETTS AG, WASHINGTON AG, OREGON AG, TEXAS AG filings
Over 8.7M records containing PII and other terabytes of internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
Most recent
5 State AG filingsMay 1, 2026 – May 28, 2026ExpandCollapse
MAWAORIATX
Massachusetts State AG
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Carnival Corporation notified Massachusetts residents of a cybersecurity event on May 27, 2026. On April 14, 2026, an unauthorized actor used social engineering/phishing to gain access to an employee account and copy personal information. The company blocked the activity, engaged third-party security experts, and is offering 24 months of complimentary TransUnion credit monitoring. The specific data elements are redacted in this template but include PII.
MA AG ≤30d
🌲Washington State AGLeaked → filing gap · 39dlinked via operator-confirmed · 100%
Carnival Corporation, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2026-04-14 and filed notice on 2026-05-27. 54,960 Washington residents were affected. 43 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 54,960
WA AG >30dLeak >30d
🦫Oregon State AGLeaked → filing gap · 39dlinked via operator-confirmed · 100%
Carnival Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2026-05-27. The breach occurred during 4/10/2026 - 4/14/2026. The breach was discovered on 4/14/2026. 5,995,277 individuals were affected. Notice was sent on 5/27/2026.
Affected (this filing): 5,995,277
Leak >30dOR AG ≤45d
🌽Iowa State AGLeaked → filing gap · 39dlinked via operator-confirmed · 100%
Carnival Corporation based in Miami, Florida, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-14 and reported on 2026-05-28. 800,060 Texas residents were affected. 5,995,277 individuals affected in total. Types of information involved: Name of individual;Address;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Date of Birth. Consumers were notified via Notice by publication in print media;Posted at company website or special website;Email.