[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCFqWYTE3_fc0QVLBiPwMt3QErEvCekUVMoWHO6cdnik":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":21,"source":22,"isVerified":4,"isSpamList":23,"isSensitive":4,"severity":24,"processingStatus":25,"logoUrl":26,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a668a7c5a0bb267223913c1","Eurail2025","Eurail 2025 Data Breach","eurail-2025","eurail.com",{"name":12,"sector":13,"country":14,"website":10},"Eurail B.V.","Travel","Netherlands","2025-12-26T00:00:00.000Z","2026-07-26T22:30:20.583Z",308777,[19,20],"Names","Passport numbers","\u003Cp>\u003Cstrong>The Eurail 2025 data breach\u003C\u002Fstrong> involved files being transferred from the European rail-pass company's network by an unauthorized actor. According to the company's notice filed with the California Attorney General, the intruder removed files on December 26, 2025. Eurail completed its review on February 25, 2026 and determined that the files contained some individuals' names and passport numbers.\u003C\u002Fp>\n\u003Cp>Eurail's filing with Oregon authorities shows that 308,777 people were affected. The company began sending written notices dated March 27, 2026 to potentially impacted individuals. LeakData uses this official person count rather than rumors or the attacker's higher claims.\u003C\u002Fp>\n\u003Ch2>Confirmed Types of Data\u003C\u002Fh2>\n\u003Cp>The individualized notices filed with US states specifically identify names and passport numbers. Those two fields may support targeted scams involving travel reservations or identity verification. Because no common set of additional fields was confirmed for every person, this record lists only names and passport numbers as data classes.\u003C\u002Fp>\n\u003Cp>Eurail previously said that it does not store bank or credit-card information or visual copies of passports. The official notice does not report passwords, payment cards, or Social Security numbers, and those fields are not added here. A passport number remains sensitive even without a document image and may be used in fraudulent booking or verification attempts.\u003C\u002Fp>\n\u003Ch2>Incident Timeline\u003C\u002Fh2>\n\u003Cp>Eurail identified unusual activity within part of its network, activated incident-response procedures, and investigated with third-party cybersecurity specialists. Evidence showed that files were transferred on December 26, 2025. The company reviewed the stolen material and determined on February 25, 2026 that personal information was present.\u003C\u002Fp>\n\u003Cp>The California filing page gives a known breach period from December 24, 2025 through January 8, 2026, while the individual notice identifies December 26 as the file-transfer date. LeakData uses the more precise transfer date for the actual data removal. Detection, scope determination, and user notification are separate events and should not be collapsed into one date.\u003C\u002Fp>\n\u003Ch2>Attacker Claims and Verified Scope\u003C\u002Fh2>\n\u003Cp>An attacker later claimed to have taken roughly 1.3 terabytes from Eurail cloud-storage, support, and source-code systems and to possess millions of Eurail or Interrail records. Eurail confirmed that a sample of stolen data had been published, but the attacker's claim about millions of people was not adopted as the official affected count.\u003C\u002Fp>\n\u003Cp>The verified regulatory notification covers 308,777 people. LeakData uses that figure and does not present alleged source code, support tickets, or database backups as confirmed user data classes. The distinction between a unilateral criminal claim and fields verified through company forensics and legal notification is preserved.\u003C\u002Fp>\n\u003Ch2>Protecting Passport Information\u003C\u002Fh2>\n\u003Cp>People who receive a direct Eurail notice should treat their passport number as involved and seek current guidance from the official passport authority in their country. Whether a document should be cancelled or replaced depends on the jurisdiction and authority's risk assessment; never send a passport image based on instructions in an email or social-media message.\u003C\u002Fp>\n\u003Cp>Watch for messages about reservation changes, visa problems, ticket refunds, or passport verification around upcoming travel. Open the Eurail or Interrail account and carrier site directly rather than using the message link. Independently verify anyone requesting a passport number, payment-card detail, or one-time security code.\u003C\u002Fp>\n\u003Ch2>Eurail's Response\u003C\u002Fh2>\n\u003Cp>Eurail said it terminated the activity after finding it, engaged outside cybersecurity professionals, and notified law enforcement. The company stated that it enhanced existing security measures to help prevent a similar incident. Written notices were issued after the review of affected files was completed.\u003C\u002Fp>\n\u003Cp>Recipients should preserve evidence of unfamiliar account or reservation activity, fraudulent travel documents, and messages using their identity information. Report observed misuse to local law enforcement, the passport authority, and the relevant travel provider. A credit freeze does not change a passport number but may provide additional protection against opening financial accounts with stolen identity details.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>The 308,777 value is Eurail's verified person count reported to the Oregon Attorney General, not the attacker's claim of millions of records. No traveler rows or passport numbers were imported into LeakData, so the absence of an email-search result cannot override a direct Eurail notice.\u003C\u002Fp>\n\u003Cp>This entry represents the December 2025 file transfer and the notification scope determined in 2026. Only names and passport numbers are confirmed data classes; banking, card, passport-image, and other undisclosed fields are excluded. If Eurail or authorities later publish a corrected count or another verified field, the content should be updated to match that official evidence.\u003C\u002Fp>","Website hack",false,"High","completed","\u002Fuploads\u002Flogo\u002Feurail_com.svg"]