2026 Amtrak — ShinyHunters Salesforce claim; HIBP loaded ~2.1M emails (firm silent in press)
Data compromised
Emails, names, addresses, support-ticket context per HIBP and press—scope disputed
Technical writeup
In mid-April 2026, ShinyHunters claimed theft of a large Amtrak dataset—often described in coverage as tied to a Salesforce-oriented customer-relationship environment—with actor marketing citing figures on the order of ~9.4 million rows while independent breach-notification aggregators took a narrower view. Have I Been Pwned added a 2026 Amtrak incident entry after reviewing leaked material, publicizing on the order of ~2.1 million unique email addresses alongside names, physical addresses, and customer-support–style records, while explicitly noting inclusion is not equivalent to Amtrak’s own confirmation. Cybernews, SC Media, and rail-industry commentary summarized the dispute. Amtrak had not issued a detailed public breach letter matching every actor claim in the first press wave indexed by BreachHistory.
Root cause
Alleged CRM / cloud account compromise via social engineering (per ShinyHunters–focused reporting)