HomeSecurityEurail: Data breach affects over 300,000 people in the US

Eurail: Data breach affects over 300,000 people in the US

The recent Eurail data breach has exposed the personal information of approximately 308,777 people in the United States , according to a disclosure by Eurail BV . This is the company that operates the official online sales platform for Eurail and Interrail rail passes. Among those affected are 242 New Hampshire residents.

Eurail data breach

The Eurail data breach occurred between late December 2025 and early January 2026, when an unauthorized actor gained access to Eurail's network and transferred files. The company discovered the problem after detecting unusual activity on its systems. It later confirmed the exposure of personal data.

Eurail: Timeline and Response to Data Breach

Following the detection of suspicious activity, Eurail activated its incident response procedures and launched an investigation with the assistance of third-party cybersecurity experts. Law enforcement authorities were also notified and are continuing to investigate the incident.5

See also: APT28 targets Ukraine with PRISMEX malware

According to the company, the unauthorized access occurred on December 26, 2025, when files were transferred from its network. The investigation concluded that these files contained personal information.

Eurail began notifying affected individuals and state authorities on March 27, 2026, reporting the breach to the attorneys general in California, New Hampshire, Oregon and Vermont. A notice was also published on the European Youth Portal.

Eurail: Data breach affects over 300,000 people in the US

What information was affected?

The company confirmed that the data breach included sensitive personal information, such as names and passport numbers . This is the confirmed exposed data for individuals in the U.S., but previous findings suggest a wider exposure is possible. For example, it has been said that financial data and health information may have been exposed .

Earlier this year, Eurail confirmed that data from a previous breach was being offered for sale on the dark web, with samples appearing on Telegram. The previous data set included reports of passport details, bank account IBANs, email addresses, phone numbers and health information, in addition to names. The combination of such data increases the risk of identity theft and financial fraud.

See also: Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

The breach is also believed to have affected customers who purchased Eurail or Interrail passes through partners, as well as participants in the DiscoverEU, which issued its own warning that sensitive personal details, including passport copies and financial information, may have been exposed.

Company Security Measures and Actions

In response to the data breach, Eurail has taken several measures, including stopping unauthorized access, strengthening internal security measures , and continuing to cooperate with law enforcement and cybersecurity experts.

Eurail said it takes the protection of customer information seriously and is working to prevent similar incidents in the future. The investigation into the full scope of the breach is ongoing

Eurail: Data breach affects over 300,000 people in the US

What Should Affected People Do?

Eurail has advised customers to be on the lookout for suspicious communications, especially requests for personal information. Users are encouraged not to share sensitive data with unknown or unsolicited contacts claiming to represent the company.

See also: Chaos botnet: New variant targets cloud misconfigurations

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The company also recommends that users monitor their financial accounts and review their credit reports regularly for any unauthorized activity. In the United States, consumers can get a free annual credit report from each of the three major credit bureaus.

Those who suspect misuse of their information are urged to contact the Federal Trade Commission, contact their state attorney general's office, and report the matter to local law enforcement.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS