Skip to main content
Back to overview
High

Amtrak Data Breach by ShinyHunters via Salesforce

We're under construction.

Key points

  • We're under construction. Please check back for an update soon. If you have ever booked a train ticket online, reserved a seat on Amtrak’s app, or reached out to Amtrak’s customer support, your personal information may now be in the hands of cybercri
  • Amtrak Data Breach by ShinyHunters via Salesforce

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality

Published
Jan 1, 2024
Updated
Aug 6, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social, Hacking, Error activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

AmtrakData DisclosureShinyHuntersSalesforce WePleaseAmtrakAmericaWhen AmtrakTheySalesforce

Quick context

Questions about this signal

What happened in this signal?

We're under construction. Please check back for an update soon. If you have ever booked a train ticket online, reserved a seat on Amtrak’s app, or reached out to Amtrak’s customer support, your personal information may now be in the hands of cybercriminals. In mid-April 2026, the notorious hacking group ShinyHunters added America’s national passenger railroad to their growing list of victims, claiming to have stolen millions of records and threatening to publish them publicly unless a ransom was paid. When Amtrak did not pay, the hackers followed through on their threat and dumped the data online.¹ This is not a small breach, and ShinyHunters is not a small-time operation. They are one of the most active and destructive cybercriminal groups operating today, and the way they got into Amtrak’s systems is a cautionary tale worth understanding. ShinyHunters claimed to have obtained 9.4 million Amtrak records via Salesforce, the widely used business software platform, threatening a public data leak without ransom payment. When Amtrak did not meet their demands, the group made good on the threat and published the stolen data publicly. The breach is now officially confirmed and catalogued. Have I Been Pwned, the widely trusted breach notification service operated by security researcher Troy Hunt, has added the Amtrak breach to its database. The published dataset contained over 2.1 million unique email addresses along with names, physical addresses, and customer support records. Have I Been Pwned is the gold standard for breach verification — if it is in their database, the data is real and the exposure is confirmed. The discrepancy between the 9.4 million records claimed by ShinyHunters and the 2.1 million unique records confirmed by Have I Been Pwned likely reflects duplicate entries or multiple records tied to the same individuals, a common pattern in Salesforce-related leaks. Notably, approximately 80% of the exposed data had already appeared in previous breaches, meaning many of the affected individuals have been through this kind of exposure before. Understanding how ShinyHunters penetrated Amtrak’s systems is important, because the method they used is not unique to this attack. They will use it again. The hackers reportedly obtained unauthorized access via Salesforce. The gang has previously targeted Salesforce employees via social engineering attacks, allowing them to obtain the access credentials of different companies using the Salesforce platform. Social engineering is not hacking in the traditional sense. There is no magic code cracking through walls of firewall protection. Instead, the attackers manipulate real human employees into handing over login credentials, often through convincing fake emails, phone calls posing as IT support, or fraudulent password reset requests. Once they had a Salesforce employee’s credentials, ShinyHunters had the keys to data belonging to every company using that employee’s system. This is the same group that used nearly identical tactics earlier in 2026 against a remarkable list of major organizations. ShinyHunters is linked to data leaks at Cisco, Hallmark, Rockstar Games, and investment advisory firms Mercer Advisors and Beacon Pointe Advisors in 2026 alone. If you have ever used Amtrak’s website, app, or customer support, the honest answer is: possibly yes. The compromised data includes names, email addresses, physical addresses, and support ticket records. While payment card data was not confirmed as part of this leak, the combination of personal details that was exposed is more than enough for criminals to attempt targeted phishing attacks, identity fraud, or account takeovers on other platforms where you use the same email address. Cybernews researchers noted that when personally identifiable information is involved, there is always a chance of social engineering attacks. The impact depends on whether the data belongs to employees or customers, and in Amtrak’s case it could be either,

When was this signal reported?

Shadow Tier lists Jan 1, 2024 as the signal date.

Which organization is connected to this signal?

Amtrak is the organization connected to this public signal.

Explore Amtrak
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence