DataBreachCaseFile.com
Investigation OpenCA AG filing · March 27, 2026

Eurail B.V. Reports December 2025 Cyberattack Incident

Eurail B.V., a provider of European train passes, formally reported a cyberattack that occurred on December 24, 2025. The company filed the incident with the California Attorney General on March 27, 2026, confirming that personal information was accessed by unauthorized parties. This exposure creates potential security risks for individuals whose data was involved.

State
CA
Breach date
December 24, 2025
Reported
March 27, 2026

Eurail B.V., a company that facilitates European train travel, officially disclosed a cybersecurity incident to the California Attorney General on March 27, 2026. The company indicated that a cyberattack took place on December 24, 2025, leading to the compromise of sensitive files on its network.

The official report confirms that unauthorized individuals gained access to systems containing customer data. While the specific categories of information involved were not detailed in the public filing, Eurail B.V. has acknowledged that personal information was exposed.

Exposure of this nature can pose various risks to affected individuals. Malicious actors may attempt to use the accessed information for purposes such as phishing scams, unauthorized account access, or efforts to commit identity theft.

Individuals who have interacted with Eurail B.V. and are concerned about this incident should remain vigilant. It is recommended to regularly review personal accounts and financial statements for any unusual or unauthorized activity. Additionally, enabling multi-factor authentication on online accounts can add an extra layer of security.

The incident remains under investigation by Eurail B.V. This filing with the California Attorney General serves as a public record of the breach.

Source: CA Attorney General filing

More CA data breach cases