Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks SecurityWeek

300,000 People Impacted by Eurail Data Breach

In December 2025, attackers breached Eurail's network and exfiltrated data from its AWS S3, Zendesk, and GitLab instances, stealing names and passport numbers of over 300,000 individuals. The stolen data, including source code and database backups, was later offered for sale on the dark web, with a sample dataset published on Telegram. Eurail has confirmed the breach and is notifying impacted individuals, noting that no financial data or visual copies of passports were stored in the compromised systems.
Read Full Article →

Data Breaches 300,000 People Impacted by Eurail Data Breach In December 2025, hackers stole names and passport numbers from the European travel company’s network. By Ionut Arghire | April 9, 2026 (4:28 AM ET) Flipboard Reddit Whatsapp Whatsapp Email European travel company Eurail is notifying over 300,000 people that their personal information was stolen in a December 2025 data breach. The incident was initially disclosed in January, when the company warned that customers who were issued a Eurail pass might have been affected. The data was stolen after hackers breached the Netherlands-based company’s network and stole files containing basic identity and contact information. In February, a hacker boasted on a surface web cybercrime site about stealing roughly 1.3 terabytes of data from Eurail’s AWS S3, Zendesk, and GitLab instances, including source code, support tickets, and database backups. The hacker claimed they stole the personal information of millions of Eurail/Interrail customers and that negotiations with the travel company had failed. In early March, Eurail confirmed that the hacker had been offering the stolen data on the dark web and that they published a sample dataset on their Telegram channel. It also said it does not store bank or credit card information, nor visual copies of passports. Advertisement. Scroll to continue reading. “Customers whose personal data was included in the sample dataset will be informed directly where contact details are available to us,” the company said. Last week, Eurail filed breach notifications with the Attorney General’s Offices in several US states, revealing that names and passport numbers were stolen in the attack. The company told the Oregon Attorney General’s Office that the data breach impacts only 308,777 people. Eurail is sending written notifications to the potentially impacted individuals. Related: FBI: Cybercrime Losses Neared $21 Billion in 2025 Related: Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption Related: European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack Related: T-Mobile Sets the Record Straight on Latest Data Breach Filing Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. More from Ionut Arghire Trent AI Emerges From Stealth With $13 Million in Funding Critical Flowise Vulnerability in Attacker Crosshairs GrafanaGhost: Attackers Can Abuse Grafana to Leak Enterprise Data Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systems German Police Unmask REvil Ransomware Leader Google DeepMind Researchers Map Web Attacks Against AI Agents Guardarian Users Targeted With Malicious Strapi NPM Packages North Korean Hackers Target High-Profile Node.js Maintainers Latest News $3.6 Million Stolen in Bitcoin Depot Hack Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long Data Leakage Vulnerability Patched in OpenSSL RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years FBI: Cybercrime Losses Neared $21 Billion in 2025 Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption Evasive Masjesu DDoS Botnet Targets IoT Devices Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing Fragile OT in an Exposed World March 10, 2026 Get a candid look at the current OT threat landscape as we move past "doom and gloom" to discuss the mechanics of modern OT exposure. Register Webinar: Why Automated Pentesting Alone Is Not Enough April 7, 2026 Join our live diagnostic session to expose hidden coverage gaps and shift from flawed tool-level evaluations to a comprehensive, program-level validation discipline. Register People on the Move Pamela McLeod has been named as CISO of the state of New Hampshire. Aspen Digital has named Matt Altomare as its new Senior Director for Cybersecurity Programs. Scott Goree has been appointed Senior Vice President of Channel and Alliances at Delinea. More People On The Move Expert Insights The New Rules of Engagement: Matching Agentic Attack Speed The cybersecurity response to AI-enabled nation-state threats cannot be incremental. It must be architectural. (Nadir Izrael) The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust Data integrity shouldn’t be seen only through the prism of a technical concern but also as a leadership issue. (Steve Durbin) Why Agentic AI Systems Need Better Governance – Lessons from OpenClaw Agentic AI platforms are shifting from passive recommendation tools to autonomous action-takers with real system access, (Etay Maor) The Human IOC: Why Security Professionals Struggle with Social Vetting Applying SOC-level rigor to the rumors, politics, and 'human intel' can make or break a security team. (Joshua Goldfarb) How to 10x Your Vulnerability Management Program in the Agentic Era The evolution of vulnerability management in the agentic era is characterized by continuous telemetry, contextual prioritization and the ultimate goal of agentic remediation. (Nadir Izrael) Flipboard Reddit Whatsapp Whatsapp Email

Share this article