In April 2026, the hacking group ShinyHunters claimed responsibility for a data breach involving Carnival, leaking approximately 8.7 million records, including 7.5 million unique email addresses tied to the Mariner Society loyalty program. The breach came after the group attempted to extort the company, and Carnival confirmed a phishing incident involving one user account, stating they are investigating the extent of the unauthorized access.