2026 Eurail B.V. — Dec network intrusion; 308,777 U.S. individuals notified; dark web sale
Data compromised
Full names, passport details, ID numbers, bank account IBANs, health information, email addresses, phone numbers
Technical writeup
Eurail B.V. (Utrecht) reported that on December 26, 2025, an unauthorized actor transferred files from a segment of its network; forensic review led to a February 25, 2026 determination that the stolen files contained personal data. The company publicly confirmed stolen data was later offered for sale on the dark web with a sample posted to Telegram, and urged password updates for the Rail Planner app. U.S. state regulator filings in late March 2026 cited 308,777 affected individuals for American notification letters (names and passport numbers emphasized in press); global totals may be higher. Related reporting referenced possible exposure of Interrail/Eurail passholders and DiscoverEU participants. Separate hacker claims cited larger terabyte-scale archives—treat as partially overlapping but not fully reconciled in open sources.
Root cause
Unauthorized network intrusion and file exfiltration
References
- https://www.securityweek.com/300000-people-impacted-by-eurail-data-breach/
- https://therecord.media/eurail-reports-data-breach-impacting-over-300000
- https://www.isssource.com/eurail-informs-u-s-victims-of-cyberattack/
- https://www.bleepingcomputer.com/news/security/eurail-says-stolen-traveler-data-now-up-for-sale-on-dark-web/
- https://www.interrail.eu/en/about-us/press-room/interrail-news/data-security-incident.html.html