The California Office of the Attorney General disclosed a data breach affecting Rail Europe North America Inc. between November 29, 2017, and February 16, 2018. The incident exposed sensitive customer information, including names, addresses, and credit/debit card details. While the exact number of affected individuals was not specified, the breach involved the potential compromise of financial and personal data, raising concerns over fraud and identity theft risks. The exposed payment card details could enable unauthorized transactions, while leaked personal information might facilitate phishing or targeted scams. The breach underscored vulnerabilities in the company’s data protection measures, particularly in safeguarding customer financial records. No evidence suggested the misuse of the stolen data at the time of reporting, but the exposure alone posed significant reputational and financial risks for both the company and its customers.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-135964
TPRM report: https://www.rankiteo.com/company/international-rail
"id": "int916082125",
"linkid": "international-rail",
"type": "Breach",
"date": "11/2017",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Travel/Tourism',
'location': 'North America',
'name': 'Rail Europe North America Inc.',
'type': 'Company'}],
'data_breach': {'data_exfiltration': 'Likely',
'personally_identifiable_information': ['names', 'addresses'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['personal information',
'payment information']},
'date_publicly_disclosed': '2018-05-08',
'description': 'The California Office of the Attorney General reported a data '
'breach involving Rail Europe North America Inc. The breach '
'occurred between November 29, 2017, and February 16, 2018, '
'exposing personal information such as names, addresses, and '
'credit/debit card details of customers.',
'impact': {'data_compromised': ['names',
'addresses',
'credit/debit card details'],
'identity_theft_risk': 'Potential',
'payment_information_risk': 'High'},
'references': [{'source': 'California Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['California Office of '
'the Attorney '
'General']},
'title': 'Rail Europe North America Inc. Data Breach (2017-2018)',
'type': 'Data Breach'}