Security Guides
Your passport number leaked, not your passport — what Carnival Corporation's data breach means for travelers
Carnival Corporation disclosed on May 27, 2026 that an employee was deceived through social engineering; a state filing lists 5,995,277 people. Passport and driver's license numbers were included. What travelers should do, and what a leaked passport number does and does not change.
For: anyone who has booked or sailed with a Carnival Corporation cruise brand, including travelers from Japan and other countries outside the US, and anyone who runs a travel or booking service that stores passport numbers. This article is based on Carnival Corporation's own notice and letter, its filings with US state attorneys general, and guidance from the US State Department, Japan's Ministry of Foreign Affairs and the FTC. It does not cover attack techniques.
What travelers should do today
Check your email for Carnival's notice — including the spam folder
Carnival says it began notifying affected people by email on or about May 27, 2026, where an address was available, and posted a substitute notice on its corporate website for people it could not reach. Each email states which items were involved for you. The notice does not list which of the group's brands affected guests sailed with, so anyone who has booked with a Carnival Corporation brand should check, including travelers outside the US. Questions go to the dedicated call center at 1-844-593-8310 (8 a.m.–8 p.m. ET, Mon–Fri).
Do not follow links in look-alike cruise emails
The leaked items are the ingredients of a convincing message: your name, contact details, date of birth and an ID number. Messages about a "refund for the incident", "passport re-verification before your next sailing" or "updating your booking details" are the ones to distrust. Do not open the link; go to the cruise line's website or app by typing the address yourself (see What is phishing?). A caller who reads out your passport number has not proved anything; that number is exactly what leaked.
US residents: freeze your credit at all three bureaus
Carnival offered two years of free credit monitoring to people in the US; the sample letter set an enrollment deadline of August 31, 2026. Independently of that offer, the FTC says a credit freeze is free, does not affect your credit score, lasts until you lift it, and while it is in place nobody can open a new credit account in your name. You must contact Equifax, Experian and TransUnion separately. Carnival's own FAQ calls a freeze or fraud alert an individual decision; for a leak that includes date of birth and an ID number, this site recommends it.
Still have your passport? Do not report it lost or stolen
The US State Department says that after you report a valid passport lost or stolen, you cannot use it for international travel even if you find it later, and reporting it does not replace it; online reports cancel the passport within one business day. That process is built for a passport that is physically gone. If your passport is in your drawer and only its number appeared in this breach, reporting it would cancel a valid document and leave you applying for a new one.
Passport actually lost or stolen? Report it right away
If the physical passport is missing, the answer flips: report it at once. For US passports, the State Department accepts reports online, by mail with Form DS-64, or in person when applying for a new passport. For Japanese passports, Japan's Ministry of Foreign Affairs says a passport reported lost becomes invalid and cannot be used even if found, and that you can file the loss report and a new application at the same time.
Travelers in Japan: watch for messages in Japanese too
The individual notices are in English, but follow-on messages do not have to be. Treat Japanese-language emails or SMS about "your cruise", "a refund" or "passport information" the same way: no links, check through the official site. If you are worried about accounts being opened in your name in Japan, the credit-bureau self-declaration explained in the Times Car breach article is one option; ask each bureau whether a leaked number qualifies.
Your passport number was in the Carnival data
Do you still have the physical passport?
↓
Yes, I have it
→ Do not report it lost or stolen (that cancels it)
→ Distrust messages that quote your number
→ US residents: credit freeze at 3 bureaus
No, it is lost or stolen
→ Report now (US: online / DS-64; Japan: loss report)
→ The old passport is canceled, even if found
→ Apply for a new passport
What happened (from Carnival Corporation's notice and state filings)
Everything below is as stated by Carnival Corporation in its notice, its sample letter to individuals and its FAQ, or as listed by state regulators.
April 10, 2026
Date the breach occurred, according to the company's filings with the Maine and California attorneys general.April 14
The company's IT security team identified unauthorized activity involving an employee's account. An unauthorized actor had used social engineering to deceive an employee. The company says it blocked the activity and began working with outside security experts.April 22
The company first determined that personal information had been copied.May 27
Notices published; emails to affected people began. The Maine filing lists 5,995,277 people.August 31
Enrollment deadline for the free US credit monitoring, per the sample letter.
- Who
- Carnival Corporation. Its individual letter describes it as the parent of Carnival Cruise Line. The notice does not break down affected people by brand or country
- Data involved
- Name, address, email address, phone number, date of birth, and government-issued ID numbers (such as driver's license and passport numbers). Varies by person; each email lists that person's items
- How access happened
- An unauthorized actor used social engineering to deceive an employee and gained access to a limited portion of the company's IT system
- Containment
- The company says it is not aware of any unauthorized activity since it stopped the activity on April 14
- Company measures
- Enhanced security and monitoring controls; law enforcement notified
- Offer
- Two years of free credit monitoring for people in the US (enrollment deadline in the sample letter: August 31, 2026)
- Contact
- 1-844-593-8310, 8 a.m.–8 p.m. ET, Mon–Fri
How to read it: brand names and bigger numbers online
Some online reports tie the incident to a particular brand's loyalty program or give larger record counts. Those details come from the party that took the data or from outside analysis, not from Carnival's notice. This article uses only what the company and state regulators have published: 5,995,277 people, and no brand-by-brand breakdown.
What a leaked passport number does and does not change
What stays the same
- The passport in your hand is still valid (nothing in the notice cancels it)
- The lost-or-stolen process is still for lost or stolen documents
- Your travel plans do not need to change because of the number alone
What changes
- An ID number stops working as proof that a caller is who they say, or knows you
- Messages can quote your real details (name, date of birth, number)
- The same number stays valid for years, until the passport expires
The weight of a passport number comes from how it is used. Travel companies typically collect it for international trips, where it sits in the booking alongside name and date of birth. That is why it feels like a password. But unlike a password, it was never secret by design: it is printed on the document and written on countless forms. What changes after a leak is trust in anyone who knows it. A message or call that quotes your passport number proves only that the sender has seen leaked data.
This site's view: a passport number should be treated like a name, not like a key
For travelers, the practical rule is: never treat knowledge of your passport number as proof of identity, in either direction. Do not trust a caller because they know it, and do not give it to a caller who asks you to "confirm" it.
For companies that hold passport numbers, the lesson from this case and from the Odido breach is the same: numbers collected for checks leak from the place that collected them. Carnival says the access began with an employee being deceived. So: keep passport data in a store that ordinary staff accounts cannot read in bulk, delete it after the sailing unless a rule requires keeping it, and put phishing-resistant sign-in (passkeys or security keys) on every account that can reach it. Why code-based MFA is not enough is covered in the DentaQuest breach.
For travel and booking services that hold ID numbers
Separate the passport store from everyday accounts
Staff who handle bookings rarely need to export passport numbers. Let them view one guest's record when needed, and give no everyday account the ability to read the whole table. That way, a deceived employee's account exposes a few records, not the whole table.
Delete after the voyage unless a rule says otherwise
Passport details are usually collected for boarding and border formalities. After the trip, list which rules require keeping them and for how long, and delete the rest automatically. Data that no longer exists cannot be copied.
Tell guests how you will and will not contact them
Publish, before anything happens, that you will never ask for a passport number by email or phone, and where guests can check messages. After a breach, that sentence is what lets guests ignore the fakes. The broader baseline is in The minimum security baseline for organizations.
Sources (public record)
The facts in this article come from the public sources below. Claims and figures from the party that took the data are not used.
- Carnival Corporation, Website Notice – Substitute Notice, Notice of Data Breach and FAQs (May 27, 2026) — carnivalcorp.com (PDF)
- Carnival Corporation, Notice of Data Breach (press release, May 27, 2026) — prnewswire.com
- Maine Attorney General, Data Breach Notification: Carnival Corporation (5,995,277 total; breach April 10, 2026; discovered April 14, 2026) — maine.gov (archived copy)
- California Attorney General, Carnival Corporation breach listing and sample individual notice (May 27, 2026) — oag.ca.gov
- Carnival Corporation, corporate website (cruise brands) — carnivalcorp.com
- US Department of State, Report Your Passport Lost or Stolen — travel.state.gov
- Ministry of Foreign Affairs of Japan, documents required for passport applications, including loss reports (Japanese) — mofa.go.jp
- FTC, Credit Freezes and Fraud Alerts — consumer.ftc.gov
Update history
2026-09-30: First version, based on Carnival Corporation's May 27, 2026 notice, FAQ and sample letter, its filings with the Maine and California attorneys general, and guidance from the US State Department, Japan's Ministry of Foreign Affairs and the FTC. This article will be updated if the company publishes new figures or details.
Read next
- The same pattern in Europe: Odido (Netherlands, passport and licence numbers leaked)
- Identity documents leaked in Japan: The Times Car breach (driver's license images)
- Another 2026 case that began with a deceived employee: The DentaQuest breach (SSNs, Medicaid and Medicare numbers)
- Follow-on scams: What is phishing?
- Stronger sign-in: Choosing multi-factor authentication / What is a passkey?
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat happened in the Carnival data breach?
According to Carnival Corporation's notice dated May 27, 2026, its IT security team identified unauthorized activity involving an employee's account on April 14, 2026. An unauthorized actor used social engineering to deceive an employee to gain access to a limited portion of the company's IT system. The company says it blocked the activity, began an investigation with outside security experts, and on April 22, 2026 first determined that personal information had been illegally copied. Law enforcement was notified.
QHow many people were affected?
Carnival Corporation's filing with the Maine Attorney General lists 5,995,277 people affected in total, including 9,746 Maine residents. The same filing gives April 10, 2026 as the date the breach occurred and April 14, 2026 as the date it was discovered. Larger figures circulating online come from the party that took the data, not from the company.
QWhat information was exposed?
Carnival's notice says the data varies by individual and includes name, address, email address, phone number, date of birth, and government-issued identification numbers such as driver's license numbers and passport numbers. Each individual email states which items were involved for that person.
QDo I need to replace my passport?
Carnival's notice does not ask anyone to replace a passport. The US State Department's lost-or-stolen process is for a passport that is lost or stolen: once reported, the passport is canceled and cannot be used for international travel even if you find it later. If you still have your passport, reporting it would cancel a valid document without replacing it. Japan's Ministry of Foreign Affairs likewise says a passport reported lost becomes invalid and cannot be used even if found.
QWhich cruise brands are covered?
The notice is issued by Carnival Corporation, and the individual letter describes the company as the parent of Carnival Cruise Line. The notice does not list which of the group's cruise brands affected customers sailed with. The company says it notified affected people by email where available; if you received that email, you are affected.
QIs free credit monitoring offered?
Carnival offered people in the US two years of free credit monitoring. The sample letter set an enrollment deadline of August 31, 2026. Separately from that offer, the FTC says a credit freeze at each of Equifax, Experian and TransUnion is free and blocks new credit accounts in your name.
QHow do I contact Carnival about the breach?
The notice gives a dedicated call center at 1-844-593-8310, 8 a.m. to 8 p.m. Eastern Time, Monday through Friday, excluding major US holidays. Use only the number in the notice or on Carnival Corporation's own website, not one given in an unexpected email or call.