LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Carnival Corporation Data Breach Notice (Washington Attorney General)

CRITICAL severityConfirmedHow we verify

Carnival Corporation Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 27, 2026
Carnival Corporation Data Breach Notice (Washington Attorney General)

Occurred April 10, 2026 · publicly disclosed May 27, 2026. Approximately 54960 people affected.

CRITICAL
Severity
54960
People affected
4
Data types exposed
May 27, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Carnival Corporation disclosed on May 27, 2026 that a data breach affecting 54,960 individuals occurred on April 10, 2026. Names, driver’s license or Washington ID card numbers, full dates of birth, and passport numbers were exposed; Washington residents should review the Attorney General’s notice and take protective steps if their information is listed.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/financial data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
54960 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Carnival Corporation has notified Washington residents that personal information was exposed in a data incident dated April 10, 2026. A filing reported to the Washington State Attorney General on May 27, 2026 states that 54,960 people were affected and lists names, driver’s license or Washington ID card numbers, full dates of birth, and passport numbers among the data involved.

For anyone who has sailed with Carnival or shared identity documents for travel, the practical stakes are straightforward: those identifiers can be misused for identity fraud, travel-related scams, or account takeovers if they reach the wrong hands. Public detail beyond the notice remains limited, so the focus for affected people is understanding what was named and taking measured steps to reduce risk.

Breaking down the breach

According to the notice filed with the Washington Attorney General, Carnival Corporation reported a data breach affecting 54,960 individuals. The incident itself is dated April 10, 2026; the company notified Washington residents in a filing reported on May 27, 2026.

The filing identifies the exposed information as including name, driver’s license or Washington ID card number, full date of birth, and passport number. The notice does not publicly detail how the incident occurred, what systems were involved, whether data was encrypted, or whether it was confirmed to have been stolen versus accessed. No threat actor is attributed in the disclosed record. Scale beyond the stated headcount of affected people, and any financial impact figures, are not provided in the facts available from the filing summary.

How a breach like this happens

Incidents that expose passenger or customer identity records often follow familiar patterns, though none of these should be read as a confirmed description of this specific event. Attackers may obtain credentials through phishing, reuse of leaked passwords, or malware on an employee device, then move laterally into databases or document stores that hold booking and travel documents. In other cases, a misconfigured cloud storage bucket, an unpatched remote-access service, or a compromised vendor with access to reservation systems can leave files reachable without multi-factor controls.

Once inside, bulk export of fields such as names, dates of birth, and government ID numbers is a common goal because those data points support identity theft and fraudulent applications. Detection sometimes lags weeks or months until unusual outbound traffic, ransom notes, or external notifications surface. Organizations then investigate, determine scope, and issue notices required by state law—exactly the kind of regulatory filing reflected in the Washington Attorney General record here. Without a public technical post-mortem for this incident, the precise path remains undisclosed.

Who is Carnival Corporation?

Carnival Corporation is one of the world’s largest cruise and leisure travel companies, operating multiple brands that carry millions of passengers each year across ocean and related vacation products. Companies in this sector routinely collect and retain the kinds of information needed to book travel, clear ports, meet customs and immigration rules, and manage onboard accounts: full legal names, dates of birth, passport details, and government-issued photo IDs, along with contact and payment data in ordinary operations.

A breach involving a major cruise operator is consequential because the same documents used to board a ship are high-value for impersonation. Passengers often provide passport and license data well in advance of sailing; that concentration of identity attributes in reservation and compliance systems raises the impact when a notice lists those fields as exposed. The Washington filing underscores that at least tens of thousands of people—specifically 54,960 in the reported figure—were in scope for this notice.

What data was at risk

The Carnival Corporation notice, as reported to the Washington State Attorney General, names the following categories as exposed: name, driver’s license or Washington ID card number, full date of birth, and passport number. Those are the only data types confirmed in the available facts.

Cruise and travel operators typically also hold addresses, phone numbers, email addresses, payment card details, loyalty account data, and emergency contacts. Whether any of those additional categories were involved in this incident is not disclosed in the filing summary and should not be assumed. Exact file formats, whether copies of ID images were included, and how long the data was accessible are likewise unconfirmed publicly.

Why it matters

Names combined with full date of birth and government ID or passport numbers are core building blocks for identity fraud. Someone with that set can attempt to open credit accounts, file false claims, impersonate a traveler, or social-engineer call centers that use those fields as authenticators. Passport numbers in particular can complicate international travel if they are abused or if a holder must replace documents after suspected misuse.

For the organization, a notice of this size brings regulatory scrutiny, notification costs, potential credit-monitoring obligations, and reputational pressure from customers who entrusted travel documents to the company. For individuals, the harm is rarely immediate drama; it is longer-tail risk—fraudulent applications that surface months later, or targeted phishing that references a real cruise booking. Calm monitoring beats panic, but ignoring a confirmed exposure of passport and license data is unwise.

Were you affected?

If you are a Washington resident who has provided identity documents to Carnival Corporation or its brands, treat the April 10, 2026 incident date and the May 27, 2026 notice as relevant until you confirm otherwise through any direct communication from the company. Public reporting puts the affected population at 54,960 people; only Carnival or official notice letters can tell you whether you are in that group.

Practical first steps include:

You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which can help you prioritize password changes and monitoring. Stay alert to official updates from Carnival or regulators rather than unverified social media claims, and keep records of any notices you receive.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyCarnival Corporation security record
52/100
DoxxScan™ · Elevated doxx risk
D+ 56Weak record

1 reported incident on record.

See Carnival Corporation’s full breach history →
RelatedMore incidents at Carnival Corporation

More recent breaches

Hibbett Retail, Inc. Data Breach Notice (Washington Attorney General)September 8, 2026LHC Group, Inc. Data Breach Notice (Washington Attorney General)September 4, 2026RB American Group LLC Data Breach Notice (Washington Attorney General)August 28, 2026Pan American Group LLC Data Breach Notice (Washington Attorney General)August 24, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Carnival Corporation Data Breach Notice (Washington Attorney General) →

Source: Washington State Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram