Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposureunderground-data-leakeducation-sector-threatcredential-access-method

ShinyHunters Claims Carnival and Udemy Breaches in Extortion Campaign

Updated 2mo agoFirst seen Apr 24, 20269 sources

ShinyHunters claimed responsibility for a major breach affecting Carnival Corporation, with data tied to Holland America Line’s Mariner Society loyalty program appearing online after an alleged extortion attempt failed. According to Have I Been Pwned, the leaked dataset contained 8.7 million records and 7.5 million unique email addresses, including names, dates of birth, genders, and loyalty program status details. Carnival acknowledged a security incident and said it had identified a phishing attack involving a single user account, while continuing to assess the scope of unauthorized access; the gang separately alleged it also stole terabytes of internal corporate data, a claim that had not been independently verified.

The same group also posted a "Pay or Leak" notice claiming it had compromised Udemy and stolen more than 1.4 million user records along with internal corporate data, giving the company a deadline before any public release. Udemy had not confirmed the incident at the time of reporting, leaving the claim unverified, but the allegation fits a broader ShinyHunters campaign targeting SaaS and education organizations through social engineering, credential theft, MFA bypass, and abuse of third-party access. The incidents underscore the group’s continued use of extortion-backed data theft to pressure victims and expose customer information.

Share:
ShinyHunters Claims Carnival and Udemy Breaches in Extortion Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 26, 20262mo ago

Udemy data is publicly leaked after ShinyHunters extortion attempt

In April 2026, data allegedly stolen from Udemy was publicly leaked following a ShinyHunters 'pay or leak' extortion attempt. The exposed dataset reportedly contained 1.4 million unique email addresses along with names, addresses, phone numbers, employer details, and instructor payout method information.

Have I Been Pwned: Udemy Data Breach
Apr 24, 20262mo ago

ShinyHunters posts alleged Udemy breach with extortion deadline

On its leak site, ShinyHunters claimed it had compromised Udemy and stolen more than 1.4 million records containing personal and internal corporate data. The post gave Udemy until 2026-04-27 to respond before the data would allegedly be leaked publicly, and the claim was unverified at publication.

ShinyHunters publicly releases alleged Carnival data

About one week after its extortion attempt, ShinyHunters publicly released a dataset allegedly tied to Carnival's Holland America Line Mariner Society program. The leak reportedly contained 8.7 million records and 7.5 million unique email addresses, including names, dates of birth, genders, and loyalty status information.

Apr 17, 20262mo ago

ShinyHunters claims Carnival breach and attempts extortion

In April 2026, ShinyHunters claimed it had stolen Carnival-related data and tried to extort the company to prevent publication. The group also alleged it had obtained customer data and terabytes of internal corporate data, though the full scope was not independently confirmed.

Carnival identifies phishing incident involving one user account

Carnival said it identified a phishing incident affecting a single user account and began assessing the scope of any unauthorized activity tied to Holland America Line's Mariner Society loyalty program.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Threat actors
1 linked
Organizations
28 linked
UdemyCarnival CorporationHolland America LineAlibaba CloudRockstar GamesHave I Been PwnedPayPalVercelGoogleMcGraw-HillContext.aiThe RegisterAdt7-ElevenAmeriprise FinancialCybernewsAuraGrubhubCrunchbaseUnacademyAmtrakCourseraZaraHallmarkAlert 360Carnival Corporation & plcUdemy, Inc.Mytheresa
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.