Eurail B.V. confirmed that customer data stolen in a previously disclosed breach is now being offered for sale on the dark web, with a sample dataset published on Telegram. The Netherlands-based rail pass operator (Eurail/Interrail), which also serves travelers in the European Commission’s DiscoverEU program, said it is still investigating the scope and impact and has engaged external cybersecurity and legal experts while working to determine which records and how many customers are affected.
Reportedly exposed data may include order and reservation details and sensitive personal information such as names, dates of birth/age, contact details (email, phone, address, country of residence), travel companion information, and in some cases passport/ID data (including photocopies), passport numbers and expiry dates, bank account references (IBAN), and health-related data. Eurail said it has notified relevant data protection authorities under GDPR and plans to issue individual notifications to impacted customers; it also advised users to be alert for phishing/scams and to update passwords (including the Rail Planner app) where credentials may have been reused.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In disclosures reported on April 8, 2026, Eurail said hackers breached its systems on December 26 and copied data affecting 308,777 people. The notices said names and passport numbers were stolen, and that the impact also extended to the DiscoverEU travel program.
On 2026-02-25, Eurail determined that files exfiltrated during the December 26, 2025 breach contained personal information. This internal assessment preceded the later customer notifications and public disclosure of the 308,777 affected individuals.
Eurail advised customers to watch for phishing and social engineering, change Rail Planner app passwords and any reused passwords, and monitor bank accounts for suspicious activity. It also published support information, including a FAQ and a contact channel for affected users.
Following confirmation that the stolen data was being sold, Eurail said it had secured its systems, engaged external cybersecurity and legal experts, and notified relevant data protection authorities under GDPR, with plans to alert authorities outside the EU. The company also said it would continue investigating the scope of the breach and notify affected customers directly where possible.
By mid-February 2026, Eurail confirmed that data stolen in the earlier breach was being offered for sale on the dark web, and that a sample of the data had been published on Telegram. Reports said the exposed information could include sensitive records such as identity details, passport data, IBANs, health information, and travel-related data.
In mid-January 2026, Eurail disclosed that attackers had gained unauthorized access to systems holding customer data. The company said personal, order, travel reservation, contact, and passport-related information may have been compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
reclaimthenet.org
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcedatabreaches.net
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.