Massive data breach at Eurail/Interrail
In January 2026, Eurail B.V., the operator of Interrail and Eurail passes, confirmed unauthorised external access to one of its systems. Customer data was accessed and copied, and Eurail is contacting affected customers directly.
What data may be involved?
- Names, dates of birth and gender
- Passport numbers
- Email addresses and phone numbers
- Physical addresses and/or countries of residence
For standard Pass purchases, Eurail says it does not store bank or credit card information and does not keep a visual copy of a passport. The categories involved vary by customer. See Eurail’s official FAQ on the personal data involved.
Eurail also says that copied data was offered for sale on the dark web and a sample was published on Telegram. See Eurail’s official FAQ on possible misuse.
What affected individuals should do
- Check your emails — Eurail should have directly informed affected customers
- Change your passwords on all platforms
- Be alert to phishing and unexpected messages about your trip
- Contact Eurail and the relevant authorities if you identify concrete misuse
- Evaluate cyber insurance