Carnival Data Breach Lawsuit — April 2026 Incident
A phishing attack on a Carnival employee account exposed personal data tied to roughly 6 million people. Three class actions were filed within days. There is no settlement and no claim form — anyone telling you otherwise is wrong.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened
On April 10, 2026, an attacker used phishing to compromise a Carnival employee account. Carnival's security team identified the unauthorized activity on April 14 and determined on April 22 that personal information had been copied.
The ransomware group ShinyHunters listed Carnival on its extortion portal around April 18 with an April 21 deadline. When Carnival did not pay, the group published the data. Have I Been Pwned verified 8.7 million records containing 7.5 million unique email addresses. Carnival's filing with the Maine Attorney General reports 5,995,277 affected individuals.
The exposure is tied specifically to the Mariner Society, the loyalty program operated by Holland America Line, a Carnival subsidiary. Verified exposed fields include names, dates of birth, gender, email addresses and loyalty-program data; the lawsuits allege phone numbers and physical addresses were also involved. Consumers were notified on May 27 — 43 days after discovery, which is the core of the complaints.
Case Details
Three putative class actions filed April 22–24, 2026 in California, Florida and Tennessee (Vasquez, Pottle, Cole). No consolidated proceeding, settlement or administrator exists as of August 2026.
Current Status
Who Is Affected
Anyone whose personal information was part of the April 2026 incident — in practice, members of the Mariner Society loyalty program (Holland America Line) and related Carnival-brand customers whose data sat in the affected systems. Carnival mailed notices starting May 27, 2026; if you received one, you are in the affected group.
You can also check whether your email address appears in the published dataset via Have I Been Pwned. Note that Carnival operates nine brands (Carnival Cruise Line, Princess, Holland America, Seabourn, Cunard and others) — the notice, not the brand you sailed with, is what tells you whether your data was involved.
What This Could Be Worth — Honestly
Timeline
- 1
April 10, 2026 — Initial access
An attacker uses phishing to compromise a Carnival employee account and reach a portion of Carnival's systems.
- 2
April 14, 2026 — Discovery
Carnival's IT security team identifies the unauthorized activity involving the employee account.
- 3
April 18–22, 2026 — Extortion and exfiltration confirmed
ShinyHunters lists Carnival on its extortion portal with an April 21 deadline. Carnival determines on April 22 that personal information was copied; when no payment is made, the data is published.
- 4
April 22–24, 2026 — Three class actions filed
Vasquez (California), Pottle (Florida) and Cole (Tennessee) file separate class actions — notably before Carnival had notified consumers.
- 5
May 27, 2026 — Consumer notification
Carnival notifies affected individuals, 43 days after discovery, and offers 24 months of TransUnion credit monitoring with enrollment open until August 31, 2026.
Scam Warnings
Large published breaches attract fraud immediately — the attackers have your email, name and date of birth, which makes their messages look convincing.
"File your Carnival settlement claim"
There is no settlement and no claim form. Any site collecting your details for a Carnival breach claim right now is either a lead broker or a scam.
Fake Carnival or Holland America "security" emails
The stolen data includes names, birth dates and loyalty details — perfect material for convincing phishing. Never click through from such an email; type the cruise line's address into your browser yourself.
"Pay a fee to release your compensation"
No legitimate class action, administrator or law firm ever asks a class member for an up-front payment, gift cards or banking logins.
Frequently Asked Questions
Is there a Carnival data breach settlement I can claim?
No. As of August 2026 the case is in active litigation — three class actions filed, no settlement agreement, no administrator and no claim deadline. The only deadline that exists today is August 31, 2026 for enrolling in the free TransUnion credit monitoring Carnival offered, which is separate from any future settlement.
Isn't this the same as the Carnival breach that already settled?
No — and this is the most common mix-up. Carnival had an earlier breach in 2019 that ended in a $1.25 million settlement with state attorneys general in 2022. That matter is closed. The April 2026 incident is a separate, much larger event with its own, still-pending lawsuits.
How do I know if my data was included?
Carnival began mailing notices on May 27, 2026 — a notice is the clearest confirmation. You can also check your email address against the published dataset on Have I Been Pwned. If you were a Mariner Society (Holland America) member, you are in the most affected group.
Should I enroll in the free credit monitoring?
Generally yes — it costs nothing and enrollment closes August 31, 2026. Accepting it does not waive your right to participate in the litigation. Read the enrollment terms yourself rather than relying on any summary, including this one.
What was actually exposed?
Verified fields in the published data include names, dates of birth, gender, email addresses and loyalty-program information. The complaints allege phone numbers and physical addresses were also involved. Carnival's own notice used a template placeholder for the data elements, so different individuals may have had different information exposed.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.