Skip to main content

Company intelligence

Eurail cybersecurity incidents and threat signals

eurail.com

Eurail logo

This company page brings together public reporting currently associated with Eurail. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

2

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

June 26, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Eurail. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Eurail

Eurail logo
Medium

Eurail Admits 1.3 TB Data Breach, Including Passports

Eurail, the European rail pass provider, admitted on May 3, 2026, to a data breach that occurred in December 2025, where hackers stole approximately 1.3 TB of data. The compromised information included names, passport numbers, national ID numbers, bank account IBANs, health information, email addresses, phone numbers, home addresses, and dates of birth for over 300,000 travelers. The stolen data was subsequently offered for sale on the dark web, with samples published on Telegram. While the breach happened in December 2025, and initial notifications began in March/April 2026, the admission of the 1.3 TB data theft and passport details was reported on May 3, 2026. [cite: 10 (initial search), 1 (new search), 2 (new search), 6 (new search)]

Eurail
Eurail logo
Medium

Eurail Data Breach Impacts Over 300,000 Individuals, Passport Data Stolen

Eurail B.V., a Netherlands-based European travel operator, suffered a data breach where an unauthorized actor transferred files from its network on December 26, 2025. The incident impacted 308,777 individuals, with attackers stealing sensitive personal information including full names, passport details, ID numbers, bank account IBANs, health information, email addresses, phone numbers, dates of birth, and postal addresses. A sample of the stolen data was subsequently published on Telegram and offered for sale on the dark web. The breach also affected participants in the EU's DiscoverEU program. Eurail detected unusual activity, initiated incident response procedures, and engaged third-party cybersecurity professionals. Notifications to affected individuals and state authorities began in March 2026.

Eurail

FAQ

Questions about Eurail cybersecurity reporting

What does the Eurail page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Eurail.

Does every mention of Eurail appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.