HackingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Eurail B.V.
bd_1e522a47a5dda280 · schema v1 · pii pii-v1
Full breach record for Eurail B.V. →Eurail B.V. notified the New Hampshire Attorney General of a cybersecurity incident affecting 242 NH residents. On December 26, 2025, an unauthorized actor transferred files containing names and passport numbers from Eurail's network. Eurail detected unusual activity, engaged third-party cybersecurity professionals, notified law enforcement, and began mailing notification letters on March 27, 2026.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_21f9fcea1b6418b6Oregon State AGfiled 2026-03-27Candidate
- bd_5de43af104915298Washington State AGfiled 2026-03-27Verified
- bd_724788a27617569bCalifornia State AGfiled 2026-03-27Verified
- bd_4fe7d1f3156f83a8Texas State AGfiled 2026-03-30(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/eurail-bv-20260327.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2026
- Raw hash
- 10caaa39f7001f26ad5073744290f6244f4ba0db9be8e4252f687b69a7664604
Reporting entity
- Name
- Eurail B.V.norm: eurail
Victim entity
- Name
- Eurail B.V.norm: eurail
Incident
- Discovered
- Dec 26, 2025
- Materiality determined
- —
- Notification sent
- Mar 27, 2026
- Affected individuals
- 242
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.