Carnival Corporation Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do
Carnival Corporation disclosed on May 27, 2026 that a data breach affecting 54,960 individuals occurred on April 10, 2026. Names, driver’s license or Washington ID card numbers, full dates of birth, and passport numbers were exposed; Washington residents should review the Attorney General’s notice and take protective steps if their information is listed.
Carnival Corporation has notified Washington residents that personal information was exposed in a data incident dated April 10, 2026. A filing reported to the Washington State Attorney General on May 27, 2026 states that 54,960 people were affected and lists names, driver’s license or Washington ID card numbers, full dates of birth, and passport numbers among the data involved.
For anyone who has sailed with Carnival or shared identity documents for travel, the practical stakes are straightforward: those identifiers can be misused for identity fraud, travel-related scams, or account takeovers if they reach the wrong hands. Public detail beyond the notice remains limited, so the focus for affected people is understanding what was named and taking measured steps to reduce risk.
Breaking down the breach
According to the notice filed with the Washington Attorney General, Carnival Corporation reported a data breach affecting 54,960 individuals. The incident itself is dated April 10, 2026; the company notified Washington residents in a filing reported on May 27, 2026.
The filing identifies the exposed information as including name, driver’s license or Washington ID card number, full date of birth, and passport number. The notice does not publicly detail how the incident occurred, what systems were involved, whether data was encrypted, or whether it was confirmed to have been stolen versus accessed. No threat actor is attributed in the disclosed record. Scale beyond the stated headcount of affected people, and any financial impact figures, are not provided in the facts available from the filing summary.
How a breach like this happens
Incidents that expose passenger or customer identity records often follow familiar patterns, though none of these should be read as a confirmed description of this specific event. Attackers may obtain credentials through phishing, reuse of leaked passwords, or malware on an employee device, then move laterally into databases or document stores that hold booking and travel documents. In other cases, a misconfigured cloud storage bucket, an unpatched remote-access service, or a compromised vendor with access to reservation systems can leave files reachable without multi-factor controls.
Once inside, bulk export of fields such as names, dates of birth, and government ID numbers is a common goal because those data points support identity theft and fraudulent applications. Detection sometimes lags weeks or months until unusual outbound traffic, ransom notes, or external notifications surface. Organizations then investigate, determine scope, and issue notices required by state law—exactly the kind of regulatory filing reflected in the Washington Attorney General record here. Without a public technical post-mortem for this incident, the precise path remains undisclosed.
Who is Carnival Corporation?
Carnival Corporation is one of the world’s largest cruise and leisure travel companies, operating multiple brands that carry millions of passengers each year across ocean and related vacation products. Companies in this sector routinely collect and retain the kinds of information needed to book travel, clear ports, meet customs and immigration rules, and manage onboard accounts: full legal names, dates of birth, passport details, and government-issued photo IDs, along with contact and payment data in ordinary operations.
A breach involving a major cruise operator is consequential because the same documents used to board a ship are high-value for impersonation. Passengers often provide passport and license data well in advance of sailing; that concentration of identity attributes in reservation and compliance systems raises the impact when a notice lists those fields as exposed. The Washington filing underscores that at least tens of thousands of people—specifically 54,960 in the reported figure—were in scope for this notice.
What data was at risk
The Carnival Corporation notice, as reported to the Washington State Attorney General, names the following categories as exposed: name, driver’s license or Washington ID card number, full date of birth, and passport number. Those are the only data types confirmed in the available facts.
Cruise and travel operators typically also hold addresses, phone numbers, email addresses, payment card details, loyalty account data, and emergency contacts. Whether any of those additional categories were involved in this incident is not disclosed in the filing summary and should not be assumed. Exact file formats, whether copies of ID images were included, and how long the data was accessible are likewise unconfirmed publicly.
Why it matters
Names combined with full date of birth and government ID or passport numbers are core building blocks for identity fraud. Someone with that set can attempt to open credit accounts, file false claims, impersonate a traveler, or social-engineer call centers that use those fields as authenticators. Passport numbers in particular can complicate international travel if they are abused or if a holder must replace documents after suspected misuse.
For the organization, a notice of this size brings regulatory scrutiny, notification costs, potential credit-monitoring obligations, and reputational pressure from customers who entrusted travel documents to the company. For individuals, the harm is rarely immediate drama; it is longer-tail risk—fraudulent applications that surface months later, or targeted phishing that references a real cruise booking. Calm monitoring beats panic, but ignoring a confirmed exposure of passport and license data is unwise.
Were you affected?
If you are a Washington resident who has provided identity documents to Carnival Corporation or its brands, treat the April 10, 2026 incident date and the May 27, 2026 notice as relevant until you confirm otherwise through any direct communication from the company. Public reporting puts the affected population at 54,960 people; only Carnival or official notice letters can tell you whether you are in that group.
Practical first steps include:
- Watch for official written notice from Carnival and follow any enrollment instructions for credit monitoring if offered.
- Place a fraud alert or credit freeze with the major credit bureaus if you believe license, passport, or date-of-birth data was yours.
- Review bank, credit card, and credit reports for unfamiliar accounts or inquiries; dispute errors promptly.
- Be skeptical of unsolicited calls or emails that reference a cruise booking or ask you to “verify” passport or license details.
- If your passport data may be involved, consider guidance from official passport authorities on reporting suspected misuse.
You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which can help you prioritize password changes and monitoring. Stay alert to official updates from Carnival or regulators rather than unverified social media claims, and keep records of any notices you receive.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Hibbett Retail, Inc. Data Breach Notice (Washington Attorney General)LHC Group, Inc. Data Breach Notice (Washington Attorney General)RB American Group LLC Data Breach Notice (Washington Attorney General)Pan American Group LLC Data Breach Notice (Washington Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.