London North Eastern Railway (LNER) has confirmed that passenger data was exposed following a cyberattack on one of its third-party suppliers.
The breach involved unauthorised access to records containing customer contact details and information relating to previous journeys. LNER said it was aware of the security incident and was treating it as a top priority. The rail operator said the information breached was limited to customer contact details and some journey history.
See also: Jaguar Land Rover: Cyberattack led to data theft

The company was quick to reassure customers that no sensitive financial data, such as bank account or payment card information, was affected. Additionally, customers' passwords remain safe as the compromised third-party system did not have access to this information.
In response to the incident, LNER is working closely with cybersecurity experts and the affected supplier to conduct a detailed investigation. The main objectives are to fully understand the scope of the unauthorised access and to ensure that appropriate security measures are in place to prevent similar incidents in the future. The company said it will provide further updates as more information becomes available through its investigation.
See also: Jaguar Land Rover closes more factories after the attack

LNER's core services, including ticket sales and train operations, were not affected at all by the security breach and customers can continue to book journeys and use services as normal. LNER has issued guidance to its customers following the breach.
Passengers are advised to be cautious of any unsolicited communications they may receive, especially those requesting personal information. These may be phishing attempts by malicious actors trying to exploit stolen data. The company clarified that there is no need for customers to contact their banks, as no financial information was compromised.
See also: Bridgestone: Cyberattack affects production

While no password data was accessed, LNER reminded customers that maintaining strong, unique passwords and changing them regularly is always good security practice. The company is focused on managing the situation and communicating transparently with those affected.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
