CSIDB logo
Incident

National Railroad Passenger Corporation

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 02:16

Linked entities

Victim
National Railroad Passenger Corporation
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Pending

Summary

The National Railroad Passenger Corporation experienced a data breach in which a dataset containing over two million unique customer records appeared on Have I Been Pwned, exposing email addresses, names, physical addresses and customer support records; estimates suggest the total may reach as high as nine million records. The breach has been linked to the ShinyHunters group, which commonly targets cloud‑based customer relationship management platforms such as Salesforce by exploiting weak access controls, misconfigurations or compromised credentials to extract large volumes of data. Attackers can use the exposed information to craft convincing impersonation and phishing attempts, increasing the risk of fraud and identity theft for affected individuals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 17, 2026, a dataset attributed to the National Railroad Passenger Corporation (Amtrak) was posted to the Have I Been Pwned breach notification service. The listing indicated that the dataset contained more than 2.1 million unique accounts. Some separate reports suggested the total number of records could be as high as 9.4 million, although Amtrak has not confirmed this higher figure. The exposed information comprised email addresses, full names, physical mailing addresses, and customer support records. The presence of support records means that details such as past trips, refund requests, or service complaints were included in the leak. The breach was first identified by security researchers monitoring the Have I Been Pwned feed.

The dataset was linked to the threat actor group ShinyHunters, which has a history of targeting cloud‑based customer relationship management platforms, particularly instances of Salesforce. Intrusions of this nature typically involve exploiting weak access controls, misconfigured cloud settings, or compromised credentials rather than penetrating internal corporate networks. Once inside the SaaS environment, the attackers can rapidly extract large volumes of data and often attempt to monetize the leak by demanding payment before releasing the information publicly. The combination of contact data and support history enables attackers to craft highly personalized phishing messages that reference specific Amtrak interactions, increasing the likelihood of successful impersonation. Amtrak has not publicly confirmed the full scope of the exposure and did not respond to requests for comment from media outlets. The incident underscores the risks associated with centralized storage of customer data in third‑party cloud services.

Sources

Sources available to members: 2 sources.

CSIDB