Skip to content
>_ITDITDWeb Security Platform

Security Guides

Your passport number leaked, not your passport — what Carnival Corporation's data breach means for travelers

Carnival Corporation disclosed on May 27, 2026 that an employee was deceived through social engineering; a state filing lists 5,995,277 people. Passport and driver's license numbers were included. What travelers should do, and what a leaked passport number does and does not change.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 13 min read

For: anyone who has booked or sailed with a Carnival Corporation cruise brand, including travelers from Japan and other countries outside the US, and anyone who runs a travel or booking service that stores passport numbers. This article is based on Carnival Corporation's own notice and letter, its filings with US state attorneys general, and guidance from the US State Department, Japan's Ministry of Foreign Affairs and the FTC. It does not cover attack techniques.

What travelers should do today

1

Check your email for Carnival's notice — including the spam folder

Carnival says it began notifying affected people by email on or about May 27, 2026, where an address was available, and posted a substitute notice on its corporate website for people it could not reach. Each email states which items were involved for you. The notice does not list which of the group's brands affected guests sailed with, so anyone who has booked with a Carnival Corporation brand should check, including travelers outside the US. Questions go to the dedicated call center at 1-844-593-8310 (8 a.m.–8 p.m. ET, Mon–Fri).

2

Do not follow links in look-alike cruise emails

The leaked items are the ingredients of a convincing message: your name, contact details, date of birth and an ID number. Messages about a "refund for the incident", "passport re-verification before your next sailing" or "updating your booking details" are the ones to distrust. Do not open the link; go to the cruise line's website or app by typing the address yourself (see What is phishing?). A caller who reads out your passport number has not proved anything; that number is exactly what leaked.

3

US residents: freeze your credit at all three bureaus

Carnival offered two years of free credit monitoring to people in the US; the sample letter set an enrollment deadline of August 31, 2026. Independently of that offer, the FTC says a credit freeze is free, does not affect your credit score, lasts until you lift it, and while it is in place nobody can open a new credit account in your name. You must contact Equifax, Experian and TransUnion separately. Carnival's own FAQ calls a freeze or fraud alert an individual decision; for a leak that includes date of birth and an ID number, this site recommends it.

4

Still have your passport? Do not report it lost or stolen

The US State Department says that after you report a valid passport lost or stolen, you cannot use it for international travel even if you find it later, and reporting it does not replace it; online reports cancel the passport within one business day. That process is built for a passport that is physically gone. If your passport is in your drawer and only its number appeared in this breach, reporting it would cancel a valid document and leave you applying for a new one.

5

Passport actually lost or stolen? Report it right away

If the physical passport is missing, the answer flips: report it at once. For US passports, the State Department accepts reports online, by mail with Form DS-64, or in person when applying for a new passport. For Japanese passports, Japan's Ministry of Foreign Affairs says a passport reported lost becomes invalid and cannot be used even if found, and that you can file the loss report and a new application at the same time.

6

Travelers in Japan: watch for messages in Japanese too

The individual notices are in English, but follow-on messages do not have to be. Treat Japanese-language emails or SMS about "your cruise", "a refund" or "passport information" the same way: no links, check through the official site. If you are worried about accounts being opened in your name in Japan, the credit-bureau self-declaration explained in the Times Car breach article is one option; ask each bureau whether a leaked number qualifies.

Your passport number was in the Carnival data

Do you still have the physical passport?

↓

Yes, I have it

→ Do not report it lost or stolen (that cancels it)

→ Distrust messages that quote your number

→ US residents: credit freeze at 3 bureaus

No, it is lost or stolen

→ Report now (US: online / DS-64; Japan: loss report)

→ The old passport is canceled, even if found

→ Apply for a new passport

The number is not the passport. Whether to report depends on whether you still hold the physical passport (based on the US State Department and Japan's Ministry of Foreign Affairs).

What happened (from Carnival Corporation's notice and state filings)

Everything below is as stated by Carnival Corporation in its notice, its sample letter to individuals and its FAQ, or as listed by state regulators.

  1. April 10, 2026

    Date the breach occurred, according to the company's filings with the Maine and California attorneys general.
  2. April 14

    The company's IT security team identified unauthorized activity involving an employee's account. An unauthorized actor had used social engineering to deceive an employee. The company says it blocked the activity and began working with outside security experts.
  3. April 22

    The company first determined that personal information had been copied.
  4. May 27

    Notices published; emails to affected people began. The Maine filing lists 5,995,277 people.
  5. August 31

    Enrollment deadline for the free US credit monitoring, per the sample letter.
5,995,277
People affected, per the company's filing with the Maine AG
Passport / DL
Government ID numbers among the data (varies by person)
8 days
From detecting the activity to confirming data was copied (Apr 14 → Apr 22)
2 years
Free credit monitoring offered to people in the US
What the company has disclosed
Who
Carnival Corporation. Its individual letter describes it as the parent of Carnival Cruise Line. The notice does not break down affected people by brand or country
Data involved
Name, address, email address, phone number, date of birth, and government-issued ID numbers (such as driver's license and passport numbers). Varies by person; each email lists that person's items
How access happened
An unauthorized actor used social engineering to deceive an employee and gained access to a limited portion of the company's IT system
Containment
The company says it is not aware of any unauthorized activity since it stopped the activity on April 14
Company measures
Enhanced security and monitoring controls; law enforcement notified
Offer
Two years of free credit monitoring for people in the US (enrollment deadline in the sample letter: August 31, 2026)
Contact
1-844-593-8310, 8 a.m.–8 p.m. ET, Mon–Fri

How to read it: brand names and bigger numbers online

Some online reports tie the incident to a particular brand's loyalty program or give larger record counts. Those details come from the party that took the data or from outside analysis, not from Carnival's notice. This article uses only what the company and state regulators have published: 5,995,277 people, and no brand-by-brand breakdown.

What a leaked passport number does and does not change

What stays the same

  • The passport in your hand is still valid (nothing in the notice cancels it)
  • The lost-or-stolen process is still for lost or stolen documents
  • Your travel plans do not need to change because of the number alone

What changes

  • An ID number stops working as proof that a caller is who they say, or knows you
  • Messages can quote your real details (name, date of birth, number)
  • The same number stays valid for years, until the passport expires

The weight of a passport number comes from how it is used. Travel companies typically collect it for international trips, where it sits in the booking alongside name and date of birth. That is why it feels like a password. But unlike a password, it was never secret by design: it is printed on the document and written on countless forms. What changes after a leak is trust in anyone who knows it. A message or call that quotes your passport number proves only that the sender has seen leaked data.

This site's view: a passport number should be treated like a name, not like a key

For travelers, the practical rule is: never treat knowledge of your passport number as proof of identity, in either direction. Do not trust a caller because they know it, and do not give it to a caller who asks you to "confirm" it.

For companies that hold passport numbers, the lesson from this case and from the Odido breach is the same: numbers collected for checks leak from the place that collected them. Carnival says the access began with an employee being deceived. So: keep passport data in a store that ordinary staff accounts cannot read in bulk, delete it after the sailing unless a rule requires keeping it, and put phishing-resistant sign-in (passkeys or security keys) on every account that can reach it. Why code-based MFA is not enough is covered in the DentaQuest breach.

For travel and booking services that hold ID numbers

1

Separate the passport store from everyday accounts

Staff who handle bookings rarely need to export passport numbers. Let them view one guest's record when needed, and give no everyday account the ability to read the whole table. That way, a deceived employee's account exposes a few records, not the whole table.

2

Delete after the voyage unless a rule says otherwise

Passport details are usually collected for boarding and border formalities. After the trip, list which rules require keeping them and for how long, and delete the rest automatically. Data that no longer exists cannot be copied.

3

Tell guests how you will and will not contact them

Publish, before anything happens, that you will never ask for a passport number by email or phone, and where guests can check messages. After a breach, that sentence is what lets guests ignore the fakes. The broader baseline is in The minimum security baseline for organizations.

Sources (public record)

The facts in this article come from the public sources below. Claims and figures from the party that took the data are not used.

  • Carnival Corporation, Website Notice – Substitute Notice, Notice of Data Breach and FAQs (May 27, 2026) — carnivalcorp.com (PDF)
  • Carnival Corporation, Notice of Data Breach (press release, May 27, 2026) — prnewswire.com
  • Maine Attorney General, Data Breach Notification: Carnival Corporation (5,995,277 total; breach April 10, 2026; discovered April 14, 2026) — maine.gov (archived copy)
  • California Attorney General, Carnival Corporation breach listing and sample individual notice (May 27, 2026) — oag.ca.gov
  • Carnival Corporation, corporate website (cruise brands) — carnivalcorp.com
  • US Department of State, Report Your Passport Lost or Stolen — travel.state.gov
  • Ministry of Foreign Affairs of Japan, documents required for passport applications, including loss reports (Japanese) — mofa.go.jp
  • FTC, Credit Freezes and Fraud Alerts — consumer.ftc.gov

Update history

2026-09-30: First version, based on Carnival Corporation's May 27, 2026 notice, FAQ and sample letter, its filings with the Maine and California attorneys general, and guidance from the US State Department, Japan's Ministry of Foreign Affairs and the FTC. This article will be updated if the company publishes new figures or details.

FAQ

QWhat happened in the Carnival data breach?
A

According to Carnival Corporation's notice dated May 27, 2026, its IT security team identified unauthorized activity involving an employee's account on April 14, 2026. An unauthorized actor used social engineering to deceive an employee to gain access to a limited portion of the company's IT system. The company says it blocked the activity, began an investigation with outside security experts, and on April 22, 2026 first determined that personal information had been illegally copied. Law enforcement was notified.

QHow many people were affected?
A

Carnival Corporation's filing with the Maine Attorney General lists 5,995,277 people affected in total, including 9,746 Maine residents. The same filing gives April 10, 2026 as the date the breach occurred and April 14, 2026 as the date it was discovered. Larger figures circulating online come from the party that took the data, not from the company.

QWhat information was exposed?
A

Carnival's notice says the data varies by individual and includes name, address, email address, phone number, date of birth, and government-issued identification numbers such as driver's license numbers and passport numbers. Each individual email states which items were involved for that person.

QDo I need to replace my passport?
A

Carnival's notice does not ask anyone to replace a passport. The US State Department's lost-or-stolen process is for a passport that is lost or stolen: once reported, the passport is canceled and cannot be used for international travel even if you find it later. If you still have your passport, reporting it would cancel a valid document without replacing it. Japan's Ministry of Foreign Affairs likewise says a passport reported lost becomes invalid and cannot be used even if found.

QWhich cruise brands are covered?
A

The notice is issued by Carnival Corporation, and the individual letter describes the company as the parent of Carnival Cruise Line. The notice does not list which of the group's cruise brands affected customers sailed with. The company says it notified affected people by email where available; if you received that email, you are affected.

QIs free credit monitoring offered?
A

Carnival offered people in the US two years of free credit monitoring. The sample letter set an enrollment deadline of August 31, 2026. Separately from that offer, the FTC says a credit freeze at each of Equifax, Experian and TransUnion is free and blocks new credit accounts in your name.

QHow do I contact Carnival about the breach?
A

The notice gives a dedicated call center at 1-844-593-8310, 8 a.m. to 8 p.m. Eastern Time, Monday through Friday, excluding major US holidays. Use only the number in the notice or on Carnival Corporation's own website, not one given in an unexpected email or call.