BreachCensus

Carnival Corporation

TransportUnited States of America

Carnival Corporation is a transport organisation in Massachusetts. It appears on the Massachusetts Attorney General breach-notification register, the California Attorney General breach-notification register, the Washington State Attorney General breach-notification register, the Texas Attorney General breach-notification register, the Vermont Attorney General breach-notification register, the Delaware Attorney General data security breach database and the Iowa Attorney General security breach notification list with 4 confirmed incidents (6 filings); the most recent notice was filed on May 28, 2026.

ISIN
GB0031215220
Wikidata
Q1044059

Data as of October 2, 2026.

Confirmed incident

Filed in MA, VT, CA, DE, IA, TX and WA — Unauthorized Access/Disclosure

The same incident was filed separately with 7 jurisdictions within a few days of each other (MA, VT, CA, DE, IA, TX and WA) — shown here as one incident.

Occurred
April 10, 2026
Disclosed
May 27, 2026
Records affected
5,995,277

Timeline

  1. May 27, 2026
    Reported to regulator Regulator

    CA AG breach notification: an unknown number of California residents affected

    source
  2. May 27, 2026
    Reported to regulator Regulator

    WA AG breach notification: 54,960 Washington residents affected

    source
  3. May 27, 2026
    Reported to regulator Regulator

    DE AG breach notification: 17,876 Delaware residents affected

    source
  4. May 27, 2026
    Reported to regulator Regulator

    IA AG breach notification: an unknown number of Iowa residents affected

    source
  5. May 27, 2026
    Reported to regulator Regulator

    DE AG breach notification: 17,876 Delaware residents affected

    source
  6. May 28, 2026
    Reported to regulator Regulator

    MA AG breach notification: 46,241 Massachusetts residents affected

    source
  7. May 28, 2026
    Reported to regulator Regulator

    TX AG breach notification: 800,060 Texas residents affected

    source
  8. May 28, 2026
    Reported to regulator Regulator

    VT AG breach notification: 3,915 Vermont residents affected

    source

Litigation

  • Possible litigation — multiple candidate dockets found, not yet resolved to a single case.
  • Possible litigation — multiple candidate dockets found, not yet resolved to a single case.
What a Massachusetts notice means

Governed by M.G.L. c. 93H. Notice to the Attorney General is required for a breach affecting any number of Massachusetts residents' personal information -- the statute sets no minimum count.

Note: the count is Massachusetts residents only, not a total.

Massachusetts breach-notification register ↗

What a Vermont notice means

Governed by 9 V.S.A. §2435. Notification to the Attorney General is required.

Note: the count is Vermont residents.

Vermont breach-notification register ↗

What a California notice means

Governed by Cal. Civ. Code §1798.82. A copy of the notification must be sent to the Attorney General when a single breach requires notifying more than 500 California residents.

Note: no affected-count is published on this register.

California breach-notification register ↗

What a Delaware notice means

Governed by 6 Del. C. §12B-102. Notice to the Attorney General is required when a breach affects more than 500 Delaware residents.

Note: the count is Delaware residents only, not a total.

Delaware breach-notification register ↗

What a Iowa notice means

Governed by Iowa Code §715C.2. Notice to the Attorney General is required within five business days of notifying consumers, for a breach requiring notification to more than 500 Iowa residents.

Note: no affected-count is published on this register.

Iowa breach-notification register ↗

What a Texas notice means

Governed by Tex. Bus. & Com. Code §521.053. Notice to the Attorney General is required when a breach affects at least 250 Texas residents.

Note: the published count is a total, not limited to Texas residents.

Texas breach-notification register ↗

What a Washington notice means

Governed by RCW 19.255.010. Notice to the Attorney General is required when a breach affects more than 500 Washington residents.

Note: the count is Washington residents only, not a total.

Washington breach-notification register ↗

Confirmed incident

US-DE

Occurred
June 4, 2020
Disclosed
December 4, 2021

Timeline

  1. December 4, 2021
    Reported to regulator Regulator

    DE AG breach notification: 729 Delaware residents affected

    source
  2. December 4, 2021
    Reported to regulator Regulator

    DE AG breach notification: 729 Delaware residents affected

    source

Litigation

  • Possible litigation — multiple candidate dockets found, not yet resolved to a single case.
Confirmed incident

Filed in MA, CA, DE and WA — Unauthorized Access/Disclosure

The same incident was filed separately with 4 jurisdictions within a few days of each other (MA, CA, DE and WA) — shown here as one incident.

Occurred
April 11, 2019
Disclosed
March 5, 2020

Timeline

  1. March 2, 2020
    Reported to regulator Regulator

    WA AG breach notification: 11,346 Washington residents affected

    source
  2. March 2, 2020
    Reported to regulator Regulator

    DE AG breach notification: 415 Delaware residents affected

    source
  3. March 2, 2020
    Reported to regulator Regulator

    DE AG breach notification: 415 Delaware residents affected

    source
  4. March 3, 2020
    Reported to regulator Regulator

    CA AG breach notification: an unknown number of California residents affected

    source
  5. March 5, 2020
    Reported to regulator Regulator

    MA AG breach notification: 2,182 Massachusetts residents affected

    source

Litigation

  • Possible litigation — multiple candidate dockets found, not yet resolved to a single case.
  • Possible litigation — multiple candidate dockets found, not yet resolved to a single case.
Unverified claim

US — Ransomware Attack

This is an unverified claim — it has allegedly happened to this organisation, as posted by a source below, but has not been confirmed by a regulator, a court filing or the organisation’s own disclosure.

Timeline

  1. April 18, 2026
    Claimed by threat actor (unverified) Claim

    Ransomware leak-site claim (ransomware_live)

    source