← Eurail B.V.

2026 Eurail B.V. — Dec network intrusion; 308,777 U.S. individuals notified; dark web sale

2026 308.8K records affected Share on X

Data compromised

Full names, passport details, ID numbers, bank account IBANs, health information, email addresses, phone numbers

Technical writeup

Eurail B.V. (Utrecht) reported that on December 26, 2025, an unauthorized actor transferred files from a segment of its network; forensic review led to a February 25, 2026 determination that the stolen files contained personal data. The company publicly confirmed stolen data was later offered for sale on the dark web with a sample posted to Telegram, and urged password updates for the Rail Planner app. U.S. state regulator filings in late March 2026 cited 308,777 affected individuals for American notification letters (names and passport numbers emphasized in press); global totals may be higher. Related reporting referenced possible exposure of Interrail/Eurail passholders and DiscoverEU participants. Separate hacker claims cited larger terabyte-scale archives—treat as partially overlapping but not fully reconciled in open sources.

Root cause

Unauthorized network intrusion and file exfiltration

References