Texas Attorney General Opens Data-Breach Investigation Into Carnival, Issues Civil Investigative Demand (2026)

Independently fact-checkedBy Recording Law Editorial Team9 min read

Independently fact-checked against primary sources (last audited June 24, 2026). · 4 primary sources cited on this page. How we verify our legal content

Texas Attorney General Opens Data-Breach Investigation Into Carnival, Issues Civil Investigative Demand (2026)

Frequently Asked Questions

Is Carnival being sued by Texas?

No. As of June 24, 2026, this is an investigation, not a lawsuit and not a finding of wrongdoing. On June 23, 2026, the Texas Attorney General announced an ongoing investigation and issued a Civil Investigative Demand, which is a request for information. No violation has been determined and no penalty has been imposed.

What is a Civil Investigative Demand?

A Civil Investigative Demand (CID) is a formal pre-suit tool that lets the Attorney General compel a company to produce documents, answer written questions, or give testimony. It helps the office decide whether the law was violated and whether to act. A CID is not a lawsuit and not a finding of liability.

How long does a company have to report a data breach in Texas?

Under Tex. Bus. & Com. Code 521.053, a business must notify affected Texans without unreasonable delay and not later than the 60th day after it determines the breach occurred. When at least 250 Texas residents are affected, the business must also notify the Texas Attorney General not later than the 30th day after determining the breach occurred.

Did Carnival violate Texas law?

That has not been determined. The Texas OAG announcement describes an investigation into whether Carnival maintained reasonable safeguards as required by Texas law. It does not state that Carnival violated any law. Carnival has reportedly said it will cooperate fully.

Was my information exposed in the Carnival breach?

A state investigation does not tell you whether your specific information was involved. Only a direct breach notice from the company can confirm that. According to the OAG and reporting, the data categories at issue reportedly included names, dates of birth, passport numbers, driver license numbers, payment information, and some health information.

How many people were affected?

According to the OAG announcement, Carnival reported 800,060 affected Texas consumers, and the total affected has been reported at approximately 6 million people. We could not independently confirm the exact six-million figure; it is attributed to the OAG and to reporting and could change as the record develops.

What Texas laws are involved?

The investigation references the Texas Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code Ch. 521), including the safeguards duty in Section 521.052 and the notification rule in Section 521.053, along with the Texas Deceptive Trade Practices Act as an enforcement hook.

What should affected consumers generally do?

As general information, consumers commonly monitor account statements and credit reports, consider a fraud alert or security freeze with the credit bureaus, and use any credit-monitoring the company offers. This is not individualized advice; consult a licensed attorney for your situation.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. Office of the Texas Attorney General press release announcing the ongoing Carnival investigation and CID (June 23, 2026)(texasattorneygeneral.gov).gov
  2. Tex. Bus. & Com. Code 521.053, Notification Required Following Breach of Security of Computerized Data(statutes.capitol.texas.gov).gov
  3. Tex. Bus. & Com. Code 521.052, Business Duty to Protect Sensitive Personal Information(statutes.capitol.texas.gov).gov
  4. Texas OAG overview of the Identity Theft Enforcement and Protection Act (Ch. 521)(texasattorneygeneral.gov).gov
Share: