ctipilot.ch

Eurail breach

incident · incident:eurail-breach-2026 single-source

Eurail breach (December 2025): 308,777 travellers notified in April 2026; the Dutch DPA and EDPS are reviewing the delayed notification.

Coverage timeline
1
first 2026-05-08 → last 2026-05-08
Peak priority
high
1 high
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Story timeline

  1. 2026-05-08Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews
    active-threats

Where this entity is cited

  • active-threats1

Source distribution

  • nos.nl1 (100%)

explore in graph

Entries about Eurail breach (1)

2026-05-08 · view entry permalink →

HIGH

Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews

Eurail began issuing breach notifications to 308 777 customers in late April 2026, revealing that an attacker accessed personal data — including passport numbers, IBANs, and DiscoverEU pass details — in a December 2025 incident. The three-month gap between discovery and notification is under review by the Autoriteit Persoonsgegevens (Dutch DPA) and the European Data Protection Supervisor (EDPS), which holds jurisdiction over EU institutional data processing. GDPR Article 33 requires supervisory authority notification within 72 hours of awareness of a breach. The exposed dataset covers travellers from EU member states who registered DiscoverEU passes; Swiss nationals who applied through bilateral arrangement may also be affected. Affected individuals should monitor for identity fraud and, where banking regulations permit, consider IBAN replacement.

incident08 May 05:00Zsingle-sourceOpen finding ↗