← Amtrak

2026 Amtrak — ShinyHunters Salesforce claim; HIBP loaded ~2.1M emails (firm silent in press)

2026 2.1M records affected Share on X

Data compromised

Emails, names, addresses, support-ticket context per HIBP and press—scope disputed

Technical writeup

In mid-April 2026, ShinyHunters claimed theft of a large Amtrak dataset—often described in coverage as tied to a Salesforce-oriented customer-relationship environment—with actor marketing citing figures on the order of ~9.4 million rows while independent breach-notification aggregators took a narrower view. Have I Been Pwned added a 2026 Amtrak incident entry after reviewing leaked material, publicizing on the order of ~2.1 million unique email addresses alongside names, physical addresses, and customer-support–style records, while explicitly noting inclusion is not equivalent to Amtrak’s own confirmation. Cybernews, SC Media, and rail-industry commentary summarized the dispute. Amtrak had not issued a detailed public breach letter matching every actor claim in the first press wave indexed by BreachHistory.

Root cause

Alleged CRM / cloud account compromise via social engineering (per ShinyHunters–focused reporting)

References