Eurail data breach: passport data for 300,000+ travellers surfaces on the dark web
TL;DR
Eurail B.V., the Utrecht-based company that sells Eurail and Interrail train passes, confirmed a security incident in January 2026 that has grown steadily in scope. US state notifications filed in early April 2026 confirm at least 308,777 affected travellers and include passport numbers and expiry dates. The intrusion itself occurred in December 2024. Stolen data was offered for sale on the dark web in mid-February and a sample was published on Telegram.
Incident Response PlaybookExpand
- Confirm the intrusion and close the exposure. For SaaS and cloud environments, that means revoking tokens, rotating keys, and tightening access policies, not only blocking an IP.
- Preserve cloud audit logs (AWS CloudTrail, Zendesk audit, GitLab audit, and equivalents) before retention windows expire.
- Reconstruct the attacker timeline across all claimed-accessed environments. Do not rely solely on what the attacker says.
- Identify all compromised credentials, access keys, and service identities. Rotate and revoke.
- Run structured forensic evidence collection across the affected cloud estate.
- Determine the actual scope of exfiltrated records versus the scope the attacker claims.
- Flag record categories that need special handling: passport numbers, ID document scans, IBAN, and any health-related data.
- Notify the Autoriteit Persoonsgegevens under AVG within 72 hours, and equivalent authorities in other jurisdictions including US state attorneys general.
- Inform the European Commission where DiscoverEU data is involved, and coordinate on participant notification.
- Notify affected travellers with specific guidance. Passport number exposure has a different remediation path than credential exposure.
- Monitor leak sites, Telegram channels, and dark web forums. Data of this kind resurfaces in stages for months.
- Post-incident review focused on cloud configuration hygiene, access-key lifecycle, and detection gaps between intrusion and discovery.
The Eurail data breach, updated
Eurail B.V., based in Utrecht, sells Eurail and Interrail train passes on behalf of a consortium of European railway operators. It also runs the ticketing side of DiscoverEU, the Erasmus+ programme that gives young Europeans free Interrail passes. That mix of customer types matters later.
The Eurail data breach was first publicly disclosed on 10 January 2026. At that point, the company described basic data exposure, including names, contact details, dates of birth, and the possibility of passport information. On 16 February 2026, multiple outlets including Dutch IT Leaders reported that stolen Eurail data was being offered for sale on the dark web, with a sample posted on Telegram. Early in April 2026, Eurail filed notifications with US state authorities. One of those notifications, reported by Treinenweb and picked up by ITdaily and Help Net Security, confirms at least 308,777 affected travellers and lists passport numbers and expiry dates among the exposed fields.
The intrusion itself, per the same notifications, occurred in December 2024. The gap between entry and public notice is close to 13 months.
This is a pattern we have seen elsewhere recently, including in our coverage of the Odido breach: initial scope is modest, subsequent scope keeps growing, and each public update tightens the definition of exactly what was taken.
What happened
According to reporting across Help Net Security, ICTMagazine, and ITdaily, the attackers claim access to Eurail's AWS S3 storage, Zendesk customer-service environment, and GitLab source-code repositories. They further claim to hold data on "millions" of travellers. The confirmed figure, based on regulatory filings, is 308,777 and counting. Attacker claims about total scope are attacker claims. They deny nothing and claim everything, which is also typical.
Eurail has not confirmed the precise attack vector. Speculation about misconfigured AWS S3 buckets circulates in the usual places; Eurail has not endorsed it, and we will not either. What is confirmed is that by 16 February, the stolen data was being offered on the dark web, and a sample was public. By early April, the data was established enough to warrant multi-jurisdiction regulatory notification.
Eurail has notified the Autoriteit Persoonsgegevens under AVG and regulators outside the EU.
Exposed data, in detail
For the general affected population of roughly 308,777 travellers, the confirmed exposed fields include order and reservation information, contact details, dates of birth, passport numbers, and passport expiry dates.
For DiscoverEU participants specifically, the European Commission has stated that additional data may be exposed, including IBAN, photocopies of passport or ID documents, and limited health-related data. That is a materially different disclosure from the general-traveller disclosure, and it matters for remediation. Scanned ID documents are worth orders of magnitude more to fraudsters than a passport number alone.
Who is affected
Two target profiles matter, and SecDesk's audience should care about the second one.
Young DiscoverEU travellers carry the heaviest consumer-protection concern. The exposure of IBAN, ID document scans, and health-related data for a population largely between 18 and 20 years old is a meaningful harm. The European Commission has communication obligations here, and public information is still being consolidated.
Business travellers whose corporate email addresses appear in the dataset are where this becomes a direct concern for Dutch and European organisations. An attacker with a real passport number, a real expiry date, a real recent travel itinerary, and a verified corporate email address can craft spearphishing messages that look indistinguishable from legitimate communication from border authorities, travel operators, or the company's own HR or travel desk. The old advice about checking sender addresses and watching for typos is not going to help when the phishing message contains accurate personal details and plausible travel context.
What this means for your organisation
The phishing fuse is lit. Expect a wave of messages over the next six to twelve months that use real stolen Eurail data as the hook. These messages will not look like phishing. They will look like a follow-up on a real train journey an employee actually took, with an accurate passport number and expiry in the message.
Alert your travel desk and HR. Anyone who handles booking changes, itinerary confirmations, or passport verifications should be briefed on this specific dataset. They are the most likely targets inside your organisation, because their day-to-day inbox contains exactly the kind of message an attacker will impersonate.
Re-examine your phishing training content. Training that emphasises obvious tells (typos, strange sender addresses, odd urgency) is about to date itself badly. The next wave of phishing using breach data like this will be linguistically clean, personally accurate, and contextually plausible. Simulation campaigns that test employees against convincing, data-backed lures rather than obvious bait reveal where your real exposure lives.
Do not rely on perimeter controls. Against a phishing email with accurate personal details, there is no firewall rule that helps. The defence is people, trained against the specific patterns these datasets enable.
Organisations that want phishing simulation and awareness training calibrated to the actual threat environment, including lures modelled on real stolen data of the kind now in circulation, can engage SecDesk's phishing-campaign programme. Trained employees are measurably harder to compromise. That is the proportionate response to a breach of this shape.
Talk to a senior responder about Eurail data breach: passport data for 300,000+ travellers surfaces on the dark web.
Schedule a response callNeed incident response?
- Two-hour SLA
- Dutch senior responders
