Eurail B.V.
ent_36570c72df37c22f0e8bf1d3
Disclosures
5
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
308,777
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Eurail B.V.
- Normalized
- eurail— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- ⭐Texas State AGas victim2026-03-30
Eurail B.V. based in Utrecht, OTHER, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-25 and reported on 2026-03-30. 4,108 Texas residents were affected. 30,877 individuals affected in total. Types of information involved: Name of individual;Government-issued ID number (e.g. passport, state ID card). Consumers were notified via Posted at company website or special website;U.S. Mail;Email.
- ⛰️New Hampshire State AGas victim2026-03-27
Eurail B.V. notified the New Hampshire Attorney General of a cybersecurity incident affecting 242 NH residents. On December 26, 2025, an unauthorized actor transferred files containing names and passport numbers from Eurail's network. Eurail detected unusual activity, engaged third-party cybersecurity professionals, notified law enforcement, and began mailing notification letters on March 27, 2026.
- 🦫Oregon State AGas victim2026-03-27
Eurail B.V. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-03-27. The breach occurred during 12/24/2025 - 1/8/2026. The breach was discovered on 2/25/2026. 308,777 individuals were affected. Notice was sent on 3/27/2026.
- 🌲Washington State AGas victim2026-03-27
Eurail B.V., a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2025-12-26 and filed notice on 2026-03-27. 1,988 Washington residents were affected. 91 days elapsed between awareness and notification. 2 days to identify the breach. 13 days to contain the breach.
- 🐻California State AGas victim2026-03-27
Eurail B.V. experienced a cyber incident in which an unauthorized actor transferred files from its network on December 26, 2025. The breach involved customer names and passport numbers. Eurail engaged third-party cybersecurity professionals, notified law enforcement, and determined affected data on February 25, 2026. Notifications were sent to affected individuals in multiple US states.