Eurail data breach impacted 308,777 people
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读用户提供的文章内容,理解主要信息。 文章标题是“Eurail数据泄露影响308,777人”,看起来是关于一次数据泄露事件。接着,文章提到黑客在2025年12月入侵了Eurail,窃取了姓名和护照数据,导致超过30万人的个人信息被曝光。Eurail是一家荷兰公司,管理并销售 Eurail Pass,允许国际旅客用一张票乘坐欧洲的火车。 文章还提到,在2026年2月,Eurail确认被窃取的数据在暗网上出售,并且样本数据被发布在Telegram上。公司已经通知了执法部门,并采取措施调查。受影响的客户包括参与欧盟DiscoverEU计划的人。泄露的数据包括订单和预订详情、基本身份和联系信息、旅行同伴信息、护照号码和有效期等。 用户的要求是用中文总结内容,控制在100字以内,并且不需要特定的开头。所以,我需要提取关键点:时间(2025年12月)、受影响人数(308,777)、泄露的数据类型(姓名、护照信息)、事件影响(暗网出售)以及公司应对措施。 现在我要把这些信息浓缩成一个简洁的句子。确保涵盖主要事件:数据泄露的时间、人数、泄露的数据类型、以及后续影响如暗网出售。同时提到公司已经采取行动应对。 最后检查字数是否在限制内,并确保语言流畅自然。 </think> 黑客于2025年12月入侵Eurail系统,窃取了308,777名旅客的姓名和护照信息等数据,并将部分数据出售至暗网。事件引发对身份盗窃和旅行信息滥用的担忧,Eurail已采取措施应对并通知受影响客户。 2026-4-9 20:42:14 Author: securityaffairs.com(查看原文) 阅读量:16 收藏

Eurail data breach impacted 308,777 people

Hackers breached Eurail in Dec 2025, stole names and passport data, and exposed over 300,000 travelers’ personal information.

Threat actors breached Eurail in December 2025 and stole names and passport numbers from its network. The company now notifies 308,777 people that attackers exposed their personal data, raising concerns about identity theft and misuse of sensitive travel information.

“We recently identified unusual activity within a segment of our network. We immediately implemented our incident response procedures, took steps to terminate the activity, and commenced an investigation with the support of third-party cybersecurity professionals. We also notified law enforcement and are supporting its investigation.” reads the data breach notification. “The evidence showed that an unauthorized actor transferred files from our network on December 26, 2025. We reviewed the files involved and, on February 25, 2026, determined that they contained some of your information.”

Eurail B.V. is a Netherlands-based company that manages and sells the Eurail Pass, allowing international travelers to explore Europe by train with a single ticket. Working with dozens of railway and ferry partners, it provides access to more than 250,000 kilometers of rail routes across over 30 European countries, simplifying cross-border rail travel.

In February, Eurail B.V. confirmed that the traveler data stolen in a breach earlier this year were being offered for sale on the dark web. The company disclosed the development as part of its ongoing response to the cybersecurity incident.

“Eurail B.V. has confirmed that certain customer data affected by the previously reported security incident has been offered for sale on the dark web and a sample data set has been published on Telegram.” reads the statement published by the company. “We are continuing to investigate the scope and impact.”

Eurail B.V. confirmed a security breach that led to unauthorized access to customer data, including participants in the European Commission’s DiscoverEU program. The company said it quickly secured its systems and launched an investigation with the help of external cybersecurity and legal experts.

Early findings indicate the breach may involve order and reservation details, basic identity and contact data, travel companion information, and in some cases passport numbers and expiry dates.

“The personal data affected may include data that users have provided (where applicable):

  • name, surname, date of birth or age, passport/ID information or photocopies,
  • email address, postal address and country of residence, phone number,
  • bank account reference (IBAN),
  • data concerning health.” reads a company update published in January.  

The company pointed out it does not store payment card data or passport copies. The company notified authorities in compliance with the GDPR regulation.

Eurail B.V. said customers whose data may have been accessed or published will be informed directly when contact details are available. They urge vigilance against suspicious calls, emails, or messages requesting personal information and stress that Eurail will never request sensitive data unsolicited. Customers should update their Rail Planner app password, review related email, social media, or banking passwords, monitor accounts for unusual activity, and report any concerns to their bank.

In early March, Eurail said the hacker sold stolen data on the dark web and shared samples on Telegram. The company said it does not store payment data or passport scans and will notify affected customers where possible.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)




文章来源: https://securityaffairs.com/190570/data-breach/eurail-data-breach-impacted-308777-people.html
如有侵权请联系:admin#unsafe.sh