Some Interrail travellers told to cancel passports as hacked data posted online
Eurail, the company behind Interrail passes, has disclosed that personal data from a December breach affecting around 300,000 travellers — including passport numbers, names, addresses, phone numbers, and dates of birth — has appeared for sale on the dark web. Some affected customers are now being advised to cancel and replace their passports.
Why this matters: Passport numbers are not like passwords. You cannot reset them in two minutes. Getting a new passport costs money, takes time, and creates real disruption, especially for people with travel already planned. Eurail knew about this breach in December. Customers found out when the data was already being sold. That gap matters. If you are in this group, your full identity profile is potentially in criminal hands. The question worth asking is why it took this long to tell 300,000 people their documents were compromised.
Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.