Cruise operators collect passport numbers because border authorities require them to. The collection is lawful, expected, and impossible for a passenger to decline. It also means the operator holds a government identity document for every guest, indefinitely, as a condition of doing business.
Carnival Corporation has reported a compromise beginning with a phishing attack on an employee account, affecting more than 5.99 million guests. Reported detection followed access in the second half of April 2026. The data described includes government identification and passport numbers.
Compelled Collection, Inherited Risk
There is a category of breach where the affected person had no meaningful choice at any point. They did not select the data fields, could not opt out of providing them, and had no visibility into how they would be retained after the trip ended.
That does not make the operator uniquely careless. It does mean the usual framing — that consumers should weigh who they trust with their data — describes nothing that actually happened here. Where collection is compelled by regulation, retention limits are the only control the passenger benefits from, and they are set entirely by the operator.
Graded medium: the vector and affected figure are consistently reported, but we have not seen the company confirm the passport field count directly.
Compiled from public reporting, listed below. We have not reviewed the affected records. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense