HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
RAIL EUROPE NORTH AMERICA INC.
bd_8e65dcbf52f85275 · schema v1 · pii pii-v1
Full breach record for RAIL EUROPE NORTH AMERICA INC. →Rail Europe North America Inc. disclosed a data breach affecting its ecommerce platform. Unauthorized access occurred from November 29, 2017, to February 16, 2018. The incident exposed customer PII, including names, addresses, credit/debit card numbers, CVVs, and user credentials. Rail Europe engaged forensic experts, isolated compromised servers, rebuilt systems, and offered credit monitoring services to affected individuals.
California clockDiscovered Feb 16, 2018 → Notified Apr 30, 201873d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_9dbec4740c5f6949Oregon State AGfiled 2018-05-08Verified
- bd_de1de524d44906b9Montana State AGfiled 2018-05-07(1d gap)Verified
- bd_9891e90aca1e59d5Washington State AGfiled 2018-04-30(8d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-135964
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2018
- Raw hash
- 4cc1460712542204cb59fc69d65654ac22e0ee1ed0724ee53b16222668b2dc84
Reporting entity
- Name
- RAIL EUROPE NORTH AMERICA INC.norm: rail europe north america
Victim entity
- Name
- RAIL EUROPE NORTH AMERICA INC.norm: rail europe north america
Incident
- Discovered
- Feb 16, 2018
- Materiality determined
- —
- Notification sent
- Apr 30, 2018
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(81 days from discovery to filing)
- Compliance flags
- CA 60-day late · 73d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 16, 2018→ Notified: Apr 30, 201873d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.