DisclosureLens
HackingTransportation & LogisticsTransportationStolen CredentialsCustomer Data InvolvedCredentialsIdentity (basic)LowResolved

Amtrak

bd_aa83163522dec153 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 16, 2020

Filed

May 28, 2020

To disclose

6 weeks

Affected

Not disclosed

Linked

4 filings

Confidence

64%
Full breach record for Amtrak4 incidents on file

On April 16, 2020, Amtrak detected unauthorized access to certain Amtrak Guest Rewards accounts using compromised usernames and passwords. The incident occurred between April 16 and April 17, 2020. Amtrak terminated access within hours, reset passwords, and engaged cybersecurity experts. No financial data or SSNs were compromised. Affected customers were offered one year of Experian IdentityWorks.

California clockDiscovered Apr 16, 2020Notified May 29, 202043d CA 60-day OK6 weeks discovery → filing

Incident timeline

discovery → filing · 6 weeks / 42 days

Apr 16, 2020

Begins

Apr 16, 2020

Discovered

May 28, 2020

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Massachusetts State AGMay 28 · first
California State AGMay 28 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.