← Blog

Trenitalia Data Breach: Italy Rail Passengers Notified After October Hack

Share on X

June 26, 2026: Italy's national rail operator Trenitalia began emailing passengers about an October 2025 cybersecurity incident that exposed personal data tied to travel tickets—while confirming payment information was not compromised.

What Trenitalia confirmed

Per ANSA and Quotidiano Nazionale, unidentified external actors accessed ticket-database personal data. Exposed categories include passenger and purchaser identity fields, contact information, itinerary details, loyalty card codes, employer names, and ID document metadata.

Trenitalia notified Italy's Data Protection Authority, CSIRT Italia, and filed a complaint with the Rome Public Prosecutor's Office.

Phishing risk

Because exposed data includes real travel dates and routes, victims face targeted phishing referencing actual trips. Trenitalia warns it will never ask for passwords or payment data by email or phone.

What to do

  1. Verify sender on any Trenitalia privacy email using official channels.
  2. Do not click links in unexpected messages citing real ticket numbers.
  3. Use the privacy webform referenced in your notification for questions.

Canonical record: Trenitalia 2026 on BreachHistory.