2026 Trenitalia — October 2025 ticket-database breach; passenger travel data notified June 2026
Data compromised
Per Trenitalia GDPR Art. 34 notices: passenger names, DOB, birthplace, contact details, travel route/date/time, ticket numbers, loyalty card codes, employer, ID document details, and ticket metadata—no account credentials or payment card data
Technical writeup
Trenitalia confirmed a cybersecurity incident detected after unauthorized access to travel-ticket personal data. The attack occurred in October 2025; the company completed forensic review before emailing affected customers on June 26, 2026 under GDPR Article 34. Exposed categories include passenger and purchaser identity data, contact information, itinerary details, loyalty codes, employer names, and ID document fields. Trenitalia states account credentials and payment card data were not affected. The company notified Italy's Data Protection Authority, CSIRT Italia, and filed a complaint with the Rome Public Prosecutor's Office. Victim count had not been publicly disclosed at catalog time.
Root cause
Unidentified external actors gained unauthorized access to Trenitalia travel-ticket databases in October 2025; customer notifications sent June 26, 2026 after forensic reconstruction