Eurail has confirmed it has experienced a security breach within its systems that resulted in unauthorised access to customer data.
A statement from the Eurail said: “Following the discovery, we immediately began work to secure our systems and initiated an investigation with the support of external cybersecurity specialists and legal advisors.
“We take this matter very seriously and are currently conducting a thorough investigation to determine the full scope of the incident and its potential impact on customers, which includes participants of the European Commission’s DiscoverEU action.”
Gary Fagan, CPO at Cytidel, said: “Travel and rail platforms like EURail depend heavily on third-party systems, meaning a breach doesn’t have to start internally to cause serious damage. Take the new DORA regulation, which came into effect for financial services in 2025. Its focus on third-party risk is a clear signal of where regulators and security attention are moving, as supply-chain security becomes a board-level concern across other industries, too.
“Most breaches today don’t rely on sophisticated techniques; they rely on exploiting known weaknesses that organisations haven’t been able to address in time. With tens of thousands of new vulnerabilities emerging every year, security teams are overwhelmed.
“Incidents like the Eurail breach highlight how difficult it has become for security teams to keep pace with the volume of change. Organisations are managing more software, more suppliers, and more threats than ever before, often without clear visibility into where the real risks sit. Without a way to track and monitor both their own exposure and that of their third parties, gaps are inevitable.”
Javvad Malik, Lead Security Awareness Advocate at KnowBe4, said: “Eurail’s disclosure is not unique, but it’s worth remembering that the real impact of breaches is felt in the long tail. Once personal data is exposed, the risk shifts from ‘IT incident’ to sustained fraud and impersonation. Organisations can’t treat notification as a compliance exercise, and they need to be clear, specific, and timely so people can take meaningful protective steps.
“From a human angle, travellers and younger users are especially vulnerable to follow‑on social engineering: convincing ‘refund’, ‘ticket reissue’, and ‘verification’ scams thrive on partial personal details”.


