ShinyHunters Breach Exposes 7.5M Emails from Carnival's Loyalty Program
Article Content
- •ShinyHunters claims to have leaked 8.7 million records from Carnival's loyalty program.
- •Carnival reported a phishing attack involving a single user account but downplayed the breach's scope.
- •The exposed data includes sensitive personal information, raising risks of phishing and fraud.
In April 2026, the hacking group ShinyHunters claimed to have breached Carnival Corporation, exposing 8.7 million records, including 7.5 million unique email addresses tied to the Mariner Society loyalty program of Holland America Line. The leaked data contains personal information such as names, dates of birth, genders, and membership status. Carnival acknowledged a phishing attack that compromised a single user account but downplayed the incident's scope. ShinyHunters, known for extortion tactics, published the data after negotiations with Carnival reportedly failed. The breach raises concerns about potential phishing and fraud targeting affected individuals. The company is currently investigating the incident and has not confirmed the full extent of the data accessed. Security experts advise affected customers to be vigilant about their email security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Carnival in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…