Ransomware victim disclosure
← All victimsCarnival Corporation & plc (carnivalcorp.com)
Claimed by shinyhunters · listed 1 month ago
Status timeline
- Listed
Apr 19, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- US
- Sector
- Hospitality and Tourism
- Listed on leak site
- Apr 19, 2026
About the victim
AI dossier — public-source company profileCarnival Corporation & plc is the world's largest leisure travel company and cruise operator, headquartered in Miami, Florida (US) and Southampton, UK. The company operates a global fleet of more than 90 ships across multiple cruise line brands, visiting over 800 ports and destinations worldwide. It is a publicly listed dual-listed company trading on both the NYSE and LSE.
- Industry
- Cruise Line Operations & Hospitality
- Employees
- 10001+
- Founded
- 1972
Attack summary
Severity: critical — Claimed exfiltration of 8.7 million PII records at scale from a major consumer-facing company constitutes a critical-level regulated data breach, likely encompassing passenger and potentially employee personal data subject to GDPR, CCPA, and other privacy regulations.ShinyHunters claims to have exfiltrated over 8.7 million records containing PII along with additional terabytes of internal corporate data, issuing a final ransom-or-leak ultimatum with a deadline of 21 April 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Personally Identifiable Information (PII) — 8.7M+ records
- Internal corporate data (terabytes)
- Customer records
What the group claims
Over 8.7M records containing PII and other terabytes of internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
Sources
- Victim sitecarnivalcorp.com
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
