TL;DR: Eurail B.V. (the company behind Interrail and Eurail train passes) confirmed that hackers broke into its systems on December 26, 2025, and walked off with personal data on 308,777 travelers. The stolen data includes passport numbers, bank account IBANs, dates of birth, and even health information. Young Europeans who used free travel passes through the EU's DiscoverEU program are among the victims. The hacker claims to have grabbed 1.3 terabytes, including source code and database backups. Samples are already circulating on Telegram, and the full dataset is for sale on the dark web. Eurail took nearly three months to determine what was actually stolen.
A Christmas Day Heist
On December 26, 2025, while most of Europe was sleeping off Christmas dinner, someone was raiding Eurail's servers. An unauthorized actor accessed the company's network and transferred files out of its systems [1].
Eurail didn't realize what was actually in those files until February 25, 2026, two full months later. That's when the company finally determined that the stolen data contained personal information belonging to hundreds of thousands of travelers [2].
By early March, the hacker had already posted sample datasets on Telegram and put the complete haul up for sale on dark web marketplaces. The attacker claimed to have exfiltrated 1.3 terabytes of data from Eurail's AWS S3 storage buckets, Zendesk support system, and GitLab repositories [3]. If true, that's not just customer data. That's source code, infrastructure credentials, and internal communications.
Eurail started notifying affected individuals on March 27, 2026. Three months after the breach. One month after the data hit the dark web.
Passport Numbers, Bank Accounts, Health Data
The list of stolen data types reads like an identity thief's wish list:
- Full names
- Dates of birth
- Passport or ID numbers (and expiry dates)
- Email addresses
- Postal addresses and country of residence
- Phone numbers
- Bank account references (IBAN)
- Health-related information
Eurail says it doesn't store payment card data or passport copies [2]. Small mercy. But passport numbers alone, combined with names, dates of birth, and addresses, are enough to attempt identity fraud, open financial accounts, or forge travel documents in some jurisdictions.
The health data is particularly concerning. Eurail hasn't specified what health information it collects or why a train pass company would need it. Accessibility requests? Medical travel needs? Whatever the reason, that data is now in criminal hands.
EU-Funded Youth Program Caught in the Blast
This isn't just about tourists who bought train passes. The European Commission's DiscoverEU program, which gives free Interrail passes to 18-year-olds across Europe, feeds its participant data through Eurail's systems [4].
The European Youth Portal confirmed that DiscoverEU travelers were among those affected. These are teenagers and young adults, many using their first passport, now facing a breach that exposed their identity documents and personal details before they've even built a credit history to monitor.
The DiscoverEU program has distributed over 800,000 travel passes since 2018. How many of those participants had their data sitting in Eurail's systems when the attacker struck isn't clear. But the program's data pipeline runs through Eurail, and the breach hit Eurail's core databases.
The European Commission told participants to change their Rail Planner app passwords. Helpful advice. Less helpful when the attacker has your passport number.
Three Months of Silence
The timeline tells its own story:
- December 26, 2025: Breach occurs, files transferred from Eurail's network
- January 2026: The Register reports on the initial breach disclosure [3]
- February 2026: Hacker publicly claims responsibility, alleges 1.3TB stolen
- February 25, 2026: Eurail determines files contained personal information
- Early March 2026: Stolen data samples appear on Telegram; full dataset listed for sale on dark web
- March 27, 2026: Eurail begins notifying affected individuals
- April 2026: U.S. state breach notifications filed in California, New Hampshire, Oregon, and Vermont
GDPR requires breach notification within 72 hours of discovery. Eurail appears to have notified authorities about the breach itself in January. But affected individuals didn't hear about it until March, after their data was already being sold. The gap between "we got breached" and "here's what was stolen" stretched to two months.
The hacker reportedly tried to negotiate with Eurail before dumping the data. Eurail has declined to comment on ransom demands [1].
What to Do if You've Used Eurail or DiscoverEU
Check Your Passport Status
Your passport number and expiry date are out there. Contact your country's passport authority about whether a replacement is warranted. Some countries flag compromised passport numbers in border systems.
Alert Your Bank
If you paid by direct debit (IBAN), tell your bank your account details were exposed. Set up transaction alerts and watch for unauthorized direct debit mandates.
Watch for Targeted Phishing
The attackers know your name, email, address, and travel history. Expect convincing emails impersonating Eurail, rail operators, or EU institutions. Don't click links. Go directly to official websites.
Change Your Rail Planner Password
Reset your Eurail/Rail Planner account password. If you reused that password anywhere else, change it there too. Use a password manager.
Travel Companies Keep Failing at Security
Eurail joins a growing list of travel companies that have fumbled customer data in 2026. Booking.com confirmed a breach on April 12 that exposed reservation details through a phishing attack on a hotel partner [5]. The travel industry sits on some of the most sensitive personal data any sector collects (passport scans, addresses, travel itineraries, payment details) and keeps proving it can't protect it.
Eurail is owned by a consortium of 35+ European railway and ferry companies. Its Rail Planner app is the gateway to Interrail and Eurail passes used by millions of travelers. The company processes data for the European Commission through DiscoverEU. This isn't a startup cutting corners. It's critical EU-backed infrastructure that stored passport numbers next to source code on the same network an attacker could ransack in a single session.
The 1.3TB claim, if accurate, means the attacker didn't just grab a database export. They rooted through AWS buckets, Zendesk tickets (which likely contain customer support conversations with personal details), and GitLab repos (which may contain credentials, API keys, and infrastructure configurations). That's not a smash-and-grab. That's a comprehensive looting of the entire digital operation.
References
- The Record - Passport numbers for more than 300,000 leaked during December Eurail data breach (April 2026)
- Security Affairs - Eurail data breach impacted 308,777 people (April 2026)
- The Register - Eurail passengers taken for a ride as data breach spills passports, bank details (January 2026)
- European Youth Portal - Data Security Incident affecting DiscoverEU travellers (2026)
- Help Net Security - Booking.com data breach notification (April 2026)