Amtrak
ent_2170323a9acc9a9a93a25988
Disclosures
11
Leak Site · State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
49,289
nationwide · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Amtrak
- Normalized
- amtrak— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- amtrak.com
Disclosure history (11)newest first
- GLOBALLeak Siteas victim2026-04-11
Over 9.4M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
- New Hampshire State AGas victim2020-11-09
Amtrak notified the New Hampshire Attorney General on November 4, 2020, regarding a security incident affecting 245 New Hampshire residents. On July 24, 2020, Amtrak detected unauthorized access to certain Amtrak Guest Rewards accounts. Usernames, passwords, and associated personal information (mailing/email addresses) were compromised. No financial data or SSNs were affected. Amtrak locked accounts, reset passwords, geo-blocked access, and engaged outside cybersecurity experts. Affected individuals received a complimentary one-year Experian IdentityWorks membership.
- Montana State AGas victim2020-11-05
Amtrak notified Montana AG of a July 24, 2020 incident where unauthorized third parties accessed Amtrak Guest Rewards accounts using compromised usernames and passwords. No financial or SSN data was compromised. Amtrak reset passwords, engaged cybersecurity experts, and offered one year of Experian IdentityWorks. The incident is resolved.
- Maine State AGas victim2020-11-04
On July 24, 2020, National Railroad Corporation (Amtrak) discovered an external system breach that occurred on the same day. The breach affected 49,289 individuals. Amtrak provided written notification to affected consumers on November 5, 2020, and offered 12 months of identity theft protection services through Experian.
- California State AGas reporting2020-11-04
National Railroad Corporation (Amtrak) detected unauthorized access to Amtrak Guest Rewards accounts on July 24, 2020. Compromised usernames and passwords were used to access accounts, potentially exposing personal information. No financial data or SSNs were compromised. The company reset passwords, implemented safeguards, and offered one year of Experian IdentityWorks. The incident is resolved.
- Washington State AGas victim2020-11-04
Amtrak notified the Washington AG of unauthorized access to certain Amtrak Guest Rewards accounts on July 24, 2020. The incident compromised usernames, passwords, and associated PII (mailing/email addresses) for 1,208 Washington residents. No financial data or SSNs were involved. Amtrak reset passwords, blocked access, engaged forensic experts, and offered one year of Experian IdentityWorks to affected individuals. Notifications were sent November 5, 2020.
- Montana State AGas victim2020-05-29
Amtrak notified Montana AG of a data breach discovered on April 16, 2020, where unauthorized third parties accessed Amtrak Guest Rewards accounts using compromised credentials. No financial or SSN data was compromised. Amtrak reset passwords, engaged forensic experts, and offered one year of Experian IdentityWorks to affected individuals.
- Indiana State AGas victim2020-05-29
Amtrak reported a data breach to the Indiana Attorney General. The breach occurred on 2020-04-16 and was reported on 2020-05-29. 109 Indiana residents were affected. 13,442 individuals affected in total.
- Massachusetts State AGas victim2020-05-28
Amtrak reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-05-28. 533 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-05-28
On April 16, 2020, Amtrak detected unauthorized access to certain Amtrak Guest Rewards accounts using compromised usernames and passwords. The incident occurred between April 16 and April 17, 2020. Amtrak terminated access within hours, reset passwords, and engaged cybersecurity experts. No financial data or SSNs were compromised. Affected customers were offered one year of Experian IdentityWorks.
- Illinois State AGas victim2020-01-01
AMTRAK filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-215). The register records the breach as discovered on April 16, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.