Eurail breach exposes 300,000+ travelers’ data

Eurail breach exposes data of 300,000+ travelers; passport numbers and contacts are reportedly for sale, prompting some to cancel passports.

Jason Kwon ·

Eurail breach exposes 300,000+ travelers’ data

Eurail , the Dutch company that sells Interrail passes, said personal information linked to more than 300,000 European travelers is being advertised for sale on the dark web after it was accessed during a security incident in December.

The company said the exposed material includes passport numbers alongside names, dates of birth, phone numbers, email addresses, and home addresses. Eurail confirmed the data was accessed during the December incident and said it has since learned the information is now being offered for sale.

Eurail recently told customers that a sample dataset had been published on Telegram. Following that notification, at least one affected customer said the UK Passport Office advised them to cancel their passport due to concerns about potential fraudulent activity, which meant applying for a replacement at a cost of £102.

A Danish customer also reported being required to cancel their passport, with replacement costs that could exceed £200. The reports highlight how the incident may translate into direct out-of-pocket expenses for some travelers, in addition to the administrative burden of replacing identity documents.

Eurail advised affected individuals to be more alert to suspicious messages and other unexpected communications. The company also urged customers to update passwords for its Rail Planner app and to change passwords for other online accounts, as a precaution following the exposure of personal details.

The company said it is still working through the process of informing everyone affected. Eurail added that preventing and limiting potential consequences remains its priority and said it was sorry for the concern caused.

More stories