National Railroad Passenger Corporation
Incident posture
Linked entities
- Victim
- National Railroad Passenger Corporation
- Threat actors
- 1 actor
- Sources
- 2 sources
Timeline
Summary
The National Railroad Passenger Corporation experienced a data breach in which a dataset containing over two million unique customer records appeared on Have I Been Pwned, exposing email addresses, names, physical addresses and customer support records; estimates suggest the total may reach as high as nine million records. The breach has been linked to the ShinyHunters group, which commonly targets cloud‑based customer relationship management platforms such as Salesforce by exploiting weak access controls, misconfigurations or compromised credentials to extract large volumes of data. Attackers can use the exposed information to craft convincing impersonation and phishing attempts, increasing the risk of fraud and identity theft for affected individuals.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 17, 2026, a dataset attributed to the National Railroad Passenger Corporation (Amtrak) was posted to the Have I Been Pwned breach notification service. The listing indicated that the dataset contained more than 2.1 million unique accounts. Some separate reports suggested the total number of records could be as high as 9.4 million, although Amtrak has not confirmed this higher figure. The exposed information comprised email addresses, full names, physical mailing addresses, and customer support records. The presence of support records means that details such as past trips, refund requests, or service complaints were included in the leak. The breach was first identified by security researchers monitoring the Have I Been Pwned feed.
The dataset was linked to the threat actor group ShinyHunters, which has a history of targeting cloud‑based customer relationship management platforms, particularly instances of Salesforce. Intrusions of this nature typically involve exploiting weak access controls, misconfigured cloud settings, or compromised credentials rather than penetrating internal corporate networks. Once inside the SaaS environment, the attackers can rapidly extract large volumes of data and often attempt to monetize the leak by demanding payment before releasing the information publicly. The combination of contact data and support history enables attackers to craft highly personalized phishing messages that reference specific Amtrak interactions, increasing the likelihood of successful impersonation. Amtrak has not publicly confirmed the full scope of the exposure and did not respond to requests for comment from media outlets. The incident underscores the risks associated with centralized storage of customer data in third‑party cloud services.
Sources
Sources available to members: 2 sources.