DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Financial accountCredentialsLowContained

Search & Book on Rail Europe

bd_26d5d9f1a5bd5eac · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 16, 2018

Filed

May 30, 2018

To disclose

15 weeks

Affected

18state residents only

Confidence

64%
Full breach record for Search & Book on Rail Europe

Rail Europe disclosed a data breach where unauthorized access occurred from June 15, 2017, to February 16, 2018. The incident compromised customer PII, including names, addresses, credit/debit card numbers (with CVV), and user credentials. Rail Europe engaged forensic experts, isolated compromised servers, rebuilt systems, and offered 12 months of identity theft protection to affected individuals.

Incident timeline

undetected · 246 days
discovery → filing · 15 weeks / 103 days

Jun 15, 2017

Begins

Feb 16, 2018

Discovered

May 30, 2018

Filed

vs. sector median

+7 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed18 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.