The Register Home Page

back to article Eurail passengers taken for a ride as data breach spills passports, bank details

Eurail has confirmed customer information was stolen in a data breach, according to notification emails sent out this week. The European travel company, also known as Interrail to EU residents, initially posted the news on January 10, but affected customers, the number of whom was not disclosed, began receiving emails on …

  1. wolfetone Silver badge

    Here's an idea

    It's mandated by government for hotels, travel agencies etc to take and record all of these bits of information.

    Why don't the government provide a facility in which to keep them in? Let the Government, who want the data, be tasked with the responsibility of holding that data.

    I mean I know why. But we should also start asking these bastards the question. And keep asking them regardless of the answer.

    1. m4r35n357 Silver badge

      Re: Here's an idea

      Another few hundred incidents like this and people might start wising up. Then again, maybe not.

    2. cdegroot

      Re: Here's an idea

      Until there's the threat of jail time (and I would call this criminally negligent behavior), nothing will change.

      1. TeeCee Gold badge

        Re: Here's an idea

        Unless you can prove that the person responsible both knew of the vulnerability exploited in their systems beforehand and did nothing about it, then they are by definition not guilty of anything.

        You cannot hold someone accountable for the illegal actions of a third party.

        Now. If you'd suggested that western intelligence agencies should be given a free hand in tracking down those responsible and ensuring that they never trouble anyone, anywhere ever again, I'd be right with you.

        1. Dan 55 Silver badge

          Re: Here's an idea

          One would hope there were audits and penalties if a business doesn't comply with the Network and Information Systems Regulations 2018 in the UK. This legislation originated in the EU so the EU version should cover Eurail as well.

        2. An_Old_Dog Silver badge

          Re: Here's an idea

          Unless you can prove that the person responsible both knew of the vulnerability exploited in their systems beforehand and did nothing about it, then they are by definition not guilty of anything.

          We need a somewhat different set of conditions to define guilt/innocence in this situation, because your conditions will excuse both intentional (head-in-the-sand) and due-to-incompetence types of ignorance of their systems' vulnerabilities.

          1. Fred Daggy Silver badge
            FAIL

            Re: Here's an idea

            It would be included in "Due Diligence" type legislation. Have you assessed all the risks?

            You don't have to do it yourself, but you need to ensure that (a) someone is doing the checks and (b) check and act on the results.

            Here is a reminder: Personal private information is a property of the person concerned. If you release it, even through accident or omission, you've taken something from them. You've taken the integrity of the information and my right to disclose it or not. Its the same as if you had lets someone charge their credit card without permission. It is theft.

            One cannot run a business without financial due diligence. Not just about making a profit - one can run at a loss. What you can't do is run a business knowing that the bills can't be paid. There is a word for that, Fraud. So, neither can you run a business knowing that there are significant risks to customer's personal data. I think we need a new word - PI3 (Personal Information Integrity Idiot). Suggestions welcome.

            1. Anonymous Coward
              Anonymous Coward

              Re: Here's an idea

              Neglegens privatum

      2. cd Silver badge

        Re: Here's an idea

        CEOs neck on a wooden block, huge man with black hood and apron carrying dull axe... they might take it seriously.

        1. Timop

          Re: Here's an idea

          That might not work as you assume.

          But what about fines? Something like 25-75% of yearly income? And after first time something happens it is extended to whole top level company board.

          Life is worthless for some but the moment they realise they might lose money....

    3. DLYONS

      Re: Here's an idea

      and you would trust a government to look after the data? Just thinking out loud.

  2. Doctor Syntax Silver badge

    "Customers whose data may have been accessed will be informed directly. We take the security of our customers' information seriously and regret any concern this incident may cause."

    Statements like this should receive a double penalty and be liable for exemplary damages to those affected.

    Media should onlyo publish them as part of an interview where they are questioned about the statement.

  3. takno

    Naturally enough the notification email went into the my spam box, and I'd probably never have seen it if it wasn't for this article.

  4. Korev Silver badge
    Coat

    Did they use Ruby on Rails?

    1. This post has been deleted by its author

  5. An_Old_Dog Silver badge

    Why Did Eurail Even *Have* Peoples' Health Data?!

    See title.

    1. parlei

      Re: Why Did Eurail Even *Have* Peoples' Health Data?!

      Almost certainly this is reasonable needs: wheel-chair or other mobility accomodation, possibly dietary needs for booked meals (e.g. gluten intolerance). Possibly vaccination status, if this is needed for travel anywhere inside the EU (the old Covid vaccination certificates?).

      But I can be wrong.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon