Skip to main content
Back to overview
Medium

Eurail Data Breach Impacts Over 300,000 Individuals, Passport Data Stolen

Eurail B.V., a Netherlands-based European travel operator, suffered a data breach where an unauthorized actor transferred files from its network on December 26, 2025.

Key points

  • Unauthorized file transfer from Eurail's network occurred on December 26, 2025.
  • Over 300,000 (specifically 308,777) individuals were impacted by the breach.
  • Stolen data includes full names, passport details, ID numbers, bank account IBANs, health information, email addresses, phone numbers, dates of birth, and postal addresses.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Dec 26, 2025
Updated
Jun 25, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

EurailData DisclosureIndividualsNetherlands-based EuropeanIBANsTelegram andDiscoverEUEurailNotificationsUnauthorized

Quick context

Questions about this signal

What happened in this signal?

Eurail B.V., a Netherlands-based European travel operator, suffered a data breach where an unauthorized actor transferred files from its network on December 26, 2025. The incident impacted 308,777 individuals, with attackers stealing sensitive personal information including full names, passport details, ID numbers, bank account IBANs, health information, email addresses, phone numbers, dates of birth, and postal addresses. A sample of the stolen data was subsequently published on Telegram and offered for sale on the dark web. The breach also affected participants in the EU's DiscoverEU program. Eurail detected unusual activity, initiated incident response procedures, and engaged third-party cybersecurity professionals. Notifications to affected individuals and state authorities began in March 2026.

When was this signal reported?

Shadow Tier lists Dec 26, 2025 as the signal date.

Which organization is connected to this signal?

Eurail is the organization connected to this public signal.

Explore Eurail
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence