---
schema: 1
kind: incident
title: "Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews"
headline: "Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews"
summary: "Eurail began notifying 308 777 travellers three months after a December 2025 breach that exposed passport numbers, IBANs, and DiscoverEU pass data. Dutch DPA and EDPS have opened reviews of the delayed notification."
discovered_at: "2026-05-08T05:00:05Z"
event_date: null
run_id: 2026-05-08-migrated
priority: high
immediate_action: null
tags:
  - data-breach
regions:
  - europe
sectors: []
entities:
  - "incident:eurail-breach-2026"
cves: []
sources:
  - url: "https://nos.nl/artikel/"
    publisher: NOS Nieuws — Eurail datalek
    role: primary
closed_sources: []
evidence: []
verification: single-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-08.md
---

Eurail began issuing breach notifications to **308 777 customers** in late April 2026, revealing that an attacker accessed personal data — including **passport numbers, IBANs, and DiscoverEU pass details** — in a December 2025 incident. The three-month gap between discovery and notification is under review by the **Autoriteit Persoonsgegevens** (Dutch DPA) and the **European Data Protection Supervisor (EDPS)**, which holds jurisdiction over EU institutional data processing. GDPR Article 33 requires supervisory authority notification within 72 hours of awareness of a breach. The exposed dataset covers travellers from EU member states who registered DiscoverEU passes; Swiss nationals who applied through bilateral arrangement may also be affected. Affected individuals should monitor for identity fraud and, where banking regulations permit, consider IBAN replacement.
