MIAMI — Carnival Corporation has started contacting customers whose personal information was compromised in an April cybersecurity incident, the company said. According to the Texas Attorney General’s Website, it includes more than 800,000 Texans. The breach, which was first detected on April 14, 2026, was triggered not by a sophisticated technical hack, but by a human vulnerability -- an employee was deceived, according to a news release from the company. "An unauthorized actor used social engineering to deceive an employee to gain access to a limited portion of the company's IT system," the company said in a notice published May 27. Carnival Cruise Line has four ships that homeport in Galveston, and the company recently announced plans to bring Carnival Tropicale to Galveston in 2028. KHOU 11 reached out to Carnival Corporate to ask for a date range when customers were affected and exact numbers. While not addressing those questions, the company did quickly respond with the following statement. "In April, we identified unauthorized access to a limited part of our IT system caused by a social engineering attack on a single user account. We immediately blocked the activity, engaged third-party security experts and alerted law enforcement. Our investigation found certain personal information was illegally accessed. We're notifying affected individuals and deeply regret any concern this causes. Protecting the privacy and security of personal data is a priority for us and we've added new layers of security and monitoring on top of the comprehensive protections already in place. We’ll also continue advancing our defenses against evolving threats." Information that Carnival said was compromised According to Carnival, the compromised information may include names, home addresses, email addresses, phone numbers, dates of birth, and government-issued identification numbers -- specifically calling out driver's license numbers and passport numbers as examples. The company cautioned
Passengers' personal information compromised in social engineering attack, says cruise line
Read the original article
khou.com →