CSIDB logo
Incident

National Railroad Passenger Corporation

Incident posture

Attack window
Apr 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
National Railroad Passenger Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Amtrak experienced a data breach involving unauthorized access to its Guest Rewards accounts, potentially compromising customers' personally identifiable information through compromised credentials or brute-force methods. The rail service confirmed that sensitive financial data and Social Security numbers were not exposed, revoked fraudulent access within hours of detection, forced password resets for affected accounts, and offered impacted individuals complimentary credit monitoring while collaborating with cybersecurity experts and law enforcement to strengthen security measures.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 16, 2020, Amtrak detected unauthorized access to its Amtrak Guest Rewards accounts, a loyalty program enabling travelers to accumulate points redeemable for discounts, hotels, and gift cards. The breach involved fraudulent access by an unknown third party using compromised usernames and passwords, indicating potential credential theft or brute-force attacks. Amtrak revoked the unauthorized access within hours of discovery. The company confirmed that while personally identifiable information (PII) was viewable in some accounts, Social Security numbers, credit card details, and other financial data remained unaffected. By April 29, 2020, Amtrak formally notified the Vermont Attorney General’s Office of the incident, disclosing that attackers had targeted customer accounts but did not penetrate core financial systems or corporate networks.

Amtrak enforced mandatory password resets for all impacted Guest Rewards accounts and offered one year of free Experian credit monitoring to affected customers. The breach highlighted broader cybersecurity risks within the travel sector, an industry frequently targeted due to its storage of sensitive customer data. Amtrak collaborated with external cybersecurity experts and law enforcement agencies to investigate the incident and implement enhanced security measures. While the exact number of compromised accounts was not disclosed, the incident followed a pattern of high-profile travel industry breaches, including contemporaneous incidents at Marriott (impacting 5.2 million guests) and easyJet (exposing data of nine million users). Amtrak’s containment actions focused on rapid access revocation and credential resets, with no reported evidence of subsequent misuse of exposed data at the time of disclosure.

Sources

Sources available to members: 1 source.

CSIDB