Carnival Corp.
Carnival Data Breach Allegedly Exposed 8.7 Million Records
A proposed class action claims Carnival Corporation failed to notify customers after hackers allegedly tied to the ShinyHunters group stole personal data — no settlement has been reached.
Key facts
- Claim deadline
- No deadline listed
- Potential payment
- Payment varies
- Proof listed
- May be required
- Status
- Open
Plain-language overview
Who may qualify?
Eligibility depends on the dates, products, locations, and other terms listed for this claim. Review any criteria below and the official terms before deciding whether it may apply to you.
- You booked or took a cruise with Carnival Corporation or one of its affiliated cruise lines — Carnival Cruise Line, Costa Cruises, Holland America Line, P&O Cruises, or Princess Cruises — before April 18, 2026, meaning your personal information was stored in the systems affected by the data breach.
Case overview
What this settlement is about
A proposed class action accuses Carnival Corporation of mishandling the fallout from a data breach that allegedly occurred on April 18, 2026. According to the complaint, personally identifiable information belonging to customers was stolen in a cyberattack allegedly linked to the ShinyHunters ransomware group, and Carnival failed to properly notify those affected. The lawsuit also alleges negligence and violations of state and federal consumer protection laws. Carnival denies any wrongdoing.
Importantly, no settlement has been reached in this case. The matter is still working through the court system and arbitration, with no final decision yet made.



