Drooid Logo
Back to story perspectives

Full Breakdown

Eurail Data Breach Highlights Digital ID Risks

4/26/2026, 8:25:50 AM

The Breach: Extensive Exposure of Travel Pass Holders’ Personal Data

Eurail, a Dutch company selling Interrail passes, suffered a breach on Dec 26 2025 that exposed passport numbers, expiry dates, names, home addresses, contact details, dates of birth, and for DiscoverEU users also passport scans, bank and health data. Eurail notified affected individuals on Mar 27 2026. A hacker accessed Eurail’s AWS S3, Zendesk and GitLab, stealing 1.3 TB; a sample appeared on Telegram; the full set is for sale on the dark web.

Background: Growing Push for Mandatory Digital Identification

Governments now require identity verification for services such as train tickets, online content, and banking. The UK’s Online Safety Act mandates age verification using IDs, prompting platforms to demand government IDs or facial scans. The EU is rolling out a European Digital Identity Wallet, and the UK is moving toward a mandatory digital ID scheme. The Eurail breach illustrates the risks of default identity collection.

Scope of the Breach: Numbers and Data Types

The breach affected 308,777 Eurail customers, exposing passport numbers, expiry dates, names, home addresses, contact details, dates of birth, and for DiscoverEU participants also passport scans, bank and health data. A sample appeared on Telegram; the full set is for sale on the dark web.

Official Statements & Responses

Eurail’s spokesperson confirmed the dark-web sale and sample dataset publication, stating that customers whose contact details are known are being directly informed. The company has not offered passport-replacement assistance; affected individuals have been told to replace passports at their own expense.

Criticism of Mandatory Digital ID Policies

Analysts argue the breach shows the assumption that identity data can be collected safely, stored securely, and kept out of the wrong hands indefinitely has never held up. They note private verification providers, not governments, hold sensitive data, raising exposure risk. The pattern is: mandatory verification -> private data collection -> breach -> victims bear consequences.

Conflicting Reports & Gaps

The sources do not state whether regulators have been notified or are investigating, nor verify the number of records sold or the hacker’s negotiation timeline. Details on remediation beyond direct notifications are lacking.

Verbatim Quotes

  • “We can confirm that data copied during the security incident has been offered for sale on the dark web and a sample dataset has been published on Telegram,” — Eurail spokesperson
  • “Customers whose personal data was included in the sample dataset are being informed directly where contact details are available to us.” — Eurail spokesperson
  • “3 terabytes of data from Eurail’s AWS S3, Zendesk, and GitLab instances, including source code, database backups, and support tickets.” — Hacker
  • “The same hacker said negotiations with Eurail had failed, which is why the files were being dumped.” — Hacker

What’s Next

The breach adds an example to the debate over mandatory digital ID schemes in the UK and the EU’s Digital Identity Wallet rollout. Affected travelers must arrange passport replacements at personal cost. Incident provides an example for policy discussions about digital-ID security.