HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
Eurail B.V.
bd_724788a27617569b · schema v1 · pii pii-v1
Full breach record for Eurail B.V. →Eurail B.V. experienced a cyber incident in which an unauthorized actor transferred files from its network on December 26, 2025. The breach involved customer names and passport numbers. Eurail engaged third-party cybersecurity professionals, notified law enforcement, and determined affected data on February 25, 2026. Notifications were sent to affected individuals in multiple US states.
California clockConsumers notified Mar 27, 2026 → AG copy submitted Mar 27, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1e522a47a5dda280New Hampshire State AGfiled 2026-03-27Verified
- bd_21f9fcea1b6418b6Oregon State AGfiled 2026-03-27Candidate
- bd_5de43af104915298Washington State AGfiled 2026-03-27Verified
- bd_4fe7d1f3156f83a8Texas State AGfiled 2026-03-30(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-620972
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2026
- Raw hash
- bd67ccec3bd493d9c2170e9571ed65f9318e246d837a1e3283dcc65db45d5224
Reporting entity
- Name
- Eurail B.V.norm: eurail
Victim entity
- Name
- Eurail B.V.norm: eurail
Incident
- Discovered
- —
- Materiality determined
- Feb 25, 2026
- Notification sent
- Mar 27, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated CollectionT1074 Data Staged
- Threat actor
- External
- Regulator citations
- Notified California Attorney GeneralNotified Connecticut Attorney GeneralNotified District of Columbia Attorney GeneralNotified Maryland Attorney GeneralNotified North Carolina Attorney General
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Mar 27, 2026→ AG copy submitted: Mar 27, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.