cyberversicherung.ch

Interrail data breach: sensitive data of Swiss travellers found on Dark Web

Published: Reading time: 1 min Sources: 2

The short answer

Customer data was copied during a security incident at Eurail/Interrail. The categories vary by person; Eurail does not store bank or credit card data or visual passport copies for standard Pass purchases.

Massive data breach at Eurail/Interrail

In January 2026, Eurail B.V., the operator of Interrail and Eurail passes, confirmed unauthorised external access to one of its systems. Customer data was accessed and copied, and Eurail is contacting affected customers directly.

What data may be involved?

  • Names, dates of birth and gender
  • Passport numbers
  • Email addresses and phone numbers
  • Physical addresses and/or countries of residence

For standard Pass purchases, Eurail says it does not store bank or credit card information and does not keep a visual copy of a passport. The categories involved vary by customer. See Eurail’s official FAQ on the personal data involved.

Eurail also says that copied data was offered for sale on the dark web and a sample was published on Telegram. See Eurail’s official FAQ on possible misuse.

What affected individuals should do

  1. Check your emails — Eurail should have directly informed affected customers
  2. Change your passwords on all platforms
  3. Be alert to phishing and unexpected messages about your trip
  4. Contact Eurail and the relevant authorities if you identify concrete misuse
  5. Evaluate cyber insurance

BTAG Versicherungsbroker AG · Bern

Have questions about cyber insurance?

BTAG clarifies your risk profile and discloses any commission before conclusion. The request does not oblige you to buy.

Quote advice by BTAG Versicherungsbroker AG, Bern — FINMA-registered insurance intermediary.

Verified primary sources
Transparent compensation