On 16 February 2026, Eurail B.V.—the Netherlands-based operator that manages and sells Eurail and Interrail passes across 250,000 kilometers of European railways—confirmed that data stolen in a breach earlier in 2026 is being offered for sale on the dark web. A threat actor also published a sample of the data on Telegram. The company stated it is still investigating the type of records and number of customers affected, but the exposed data categories represent a severe compromise of traveler identity and financial information.
What was compromised
According to Eurail's disclosure and updates, the breach exposed:
- Identity documents: Full names, passport details, national ID numbers
- Financial data: Bank account IBANs (International Bank Account Numbers)
- Health information: Medical or health-related data stored in customer profiles
- Contact details: Email addresses, phone numbers
The combination of passport data and IBANs is particularly concerning: it enables identity theft, bank fraud, and targeted phishing at scale. Passport numbers and ID documents can be used to open accounts, apply for credit, or bypass Know Your Customer (KYC) checks. IBANs allow direct debit fraud or unauthorized transfers in jurisdictions where SEPA direct debits are common.
Technical context: Attack surface
Eurail B.V. operates a travel platform that serves millions of travelers annually, including participants in the EU's DiscoverEU program for young Europeans. The customer database necessarily aggregates:
- Booking and reservation data
- Payment information (card and bank details for direct debit)
- Identity verification data (passport/ID for cross-border travel)
- Health-related fields (e.g., accessibility requirements, medical conditions for travel insurance)
Unauthorized access to such a database typically results from:
- Compromised credentials — Phishing, credential stuffing, or infostealer malware on employee or contractor accounts
- Third-party or supply-chain compromise — Access via a payment processor, booking engine, or cloud service provider
- Vulnerability exploitation — SQL injection, API abuse, or misconfigured cloud storage
Eurail has not publicly disclosed the specific attack vector or whether the threat actor has been identified. The company stated it continues to investigate which specific data records and how many customers are affected, and will send individual notifications to those impacted.
Dark web distribution
The threat actor's decision to offer the data for sale on the dark web and publish a sample on Telegram follows a common data extortion pattern: demonstrate authenticity to attract buyers, pressure the victim, and monetize the stolen dataset. Sample publication also serves as proof-of-concept for potential purchasers and can trigger secondary scams (e.g., fake "breach notification" phishing emails).
Eurail has notified data protection authorities in accordance with GDPR requirements and will alert authorities outside the EU. The company published a FAQ page for affected customers and directs concerns to [email protected].
Why passport and IBAN exposure matters
Unlike email and phone numbers—which are frequently exposed in breaches—passport details and IBANs are high-value identifiers:
- Passport numbers are difficult to change and are used for border control, KYC, and account verification. Stolen passport data can support synthetic identity fraud and document forgery.
- IBANs enable SEPA direct debits across the Eurozone. Attackers can set up unauthorized mandates or attempt account takeover with combined PII.
- Health information is sensitive under GDPR and national laws; exposure can lead to discrimination, blackmail, or targeted scams.
Recommendations for affected customers
- Update Rail Planner app password — Eurail recommends resetting your account password and using a unique password on any other platform where you reuse credentials.
- Monitor bank accounts — Watch for unauthorized transactions or new direct debit mandates. Report suspicious activity to your bank immediately.
- Beware of phishing — Expect emails or calls referencing Eurail, Interrail, or travel bookings. Verify any links or requests via the official eurail.com or interrail.eu sites.
- Consider a credit freeze — If identity documents were exposed, consider placing a freeze on your credit file to prevent unauthorized account openings.
- Check official communications — Eurail will notify affected individuals; be cautious of unsolicited messages claiming to be from Eurail.
Bottom line
The Eurail breach underscores the risk to travel and hospitality platforms that aggregate identity, payment, and health data. The exposure of passport details and IBANs creates long-term fraud and identity theft risk for affected travelers. For full breach details, timeline, and technical writeup, see Eurail 2026 breach on BreachHistory.
Sources: BleepingComputer, TechRadar