2026 Viking Line — bytetobreach passenger + payment-API claim (unverified)
Data compromised
Actor-claimed: full traveler personal information including vehicle plates; complementary NetAxept onboard payment/transaction correlation—no attested person count
Technical writeup
Unverified leak-site / forum claim — March 11, 2026. Dark Web Informer reported actor bytetobreach claiming a Viking Line passenger database (including plates) offered for free download, plus a NetAxept payment-API dataset correlating passengers with onboard transactions. Actor described a 2021-era Solr LFI to Tomcat credentials, JSP reverse shell, and pivot to a master server. No public person count; Viking Line had not confirmed in sources reviewed. recordsAffected remains 0.
Root cause
Unverified bytetobreach claim of ferry passenger DB theft plus NetAxept payment-API correlation via Solr LFI / Tomcat pivot—company had not confirmed at catalog time