Eurail (Interrail in the EU) confirmed a data breach in which customer information was stolen, with affected customers notified via email after the company initially posted a notice about the incident. Reported exposed data includes names, dates of birth, gender, email addresses, home addresses, phone numbers, and passport details (number, issuing country, and expiration date). Eurail stated that it is monitoring for misuse and warned customers about downstream risks such as phishing, spoofing, unauthorized account access, and identity theft, and it set up customer support/FAQ guidance.
For travelers who obtained passes via the EU’s DiscoverEU program, the European Commission issued a separate notice indicating potentially broader exposure beyond Eurail’s standard dataset, including ID document copies, bank account reference details (e.g., IBAN/bank reference numbers), and health data. Eurail indicated that customers who purchased directly did not have visual copies of passports stored, but DiscoverEU participants may have had such copies processed/stored as part of program requirements, increasing the sensitivity of the compromised data set.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
By January 15, 2026, Eurail had set up a FAQ page to support affected customers and expanded its advice on password changes. It recommended updating credentials not only for the Rail Planner app but also for linked email, social media, and online banking accounts.
As of January 14, 2026, Eurail said it had found no evidence that the stolen data had been misused or publicly disclosed. The company said its investigation was ongoing to determine the full scope of accessed and copied data.
By January 14, 2026, the European Commission had issued a separate notice stating that DiscoverEU participants may have had additional sensitive data exposed. This potentially included ID photocopies, bank account reference numbers or IBANs, and some health-related data.
Eurail began sending notification emails to affected customers on January 13, 2026. The notices warned of risks such as phishing, spoofing, unauthorized access, fraud, and identity theft, and advised users to change passwords.
Eurail notified relevant regulators about the breach, including the Dutch data protection authority, and reporting also indicates notification to the European Data Protection Supervisor. These disclosures were made as part of its regulatory response under applicable data protection rules.
Following discovery of the incident, Eurail said it secured the affected systems, closed the exploited vulnerability, reset credentials, and enhanced security controls. The company also engaged external cybersecurity specialists while its investigation continued.
On January 10, 2026, Eurail publicly disclosed that an attacker had gained unauthorized access to its IT systems and stolen customer data. The company said affected information included identity and contact details, and in some cases passport or ID-related data.
On December 26, 2025, an unauthorized actor accessed a segment of Eurail's network and transferred files from it. Later disclosures indicate the compromised files included personal information such as names and passport numbers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
oag.ca.gov
Open sourcehelpnetsecurity.com
Open sourcerescana.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourceoag.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.