RAIL EUROPE NORTH AMERICA INC.
bd_8e65dcbf52f85275 · schema v1 · pii pii-v1
Full breach record for RAIL EUROPE NORTH AMERICA INC. →Rail Europe North America Inc. disclosed that unauthorized persons gained access to its ecommerce websites' IT platform between November 29, 2017, and February 16, 2018. The incident was discovered on February 16, 2018. Affected data may include names, addresses, phone numbers, emails, credit/debit card numbers, expiration dates, CVVs, and in some cases, usernames and passwords. The company contained the incident by disconnecting servers and engaged forensic experts. It rebuilt systems, hardened security, and offered identity theft protection services to affected customers.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 29, 2017
Begins
Feb 16, 2018
Discovered
May 8, 2018
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Oregon State AGbd_9dbec4740c5f69492018-05-08Verified
- Massachusetts State AGbd_ff2b6f42fa0c94432018-05-08Verified
- Montana State AGbd_de1de524d44906b92018-05-07 · +1dVerified
- Washington State AGbd_9891e90aca1e59d52018-04-30 · +8dCandidate
Show 1 more filing ↓Show fewer ↑up to 14d gap
- New Hampshire State AGbd_63b6ec325c6f6bce2018-04-24 · +14dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Apr 24 (NH), last May 8 (CA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.