Data breach
Amtrak
- Records
- 2,258,758
- Breach date
- 11 April 2026Estimated
- Added
- 20 April 2026
What was exposed
4 types of data
- Names2,258,758
- Email addresses2,199,615
- Street addresses1,584,654
- Phone numbers974,628
About this breach
A dataset containing information tied to Amtrak customers surfaced online in April 2026, and our investigation team has indexed roughly 2.26 million records linked to the passenger railroad company. The intrusion has been attributed in media reporting to ShinyHunters, a threat actor group known for targeting cloud-based customer management systems at large companies. According to our investigation team, the estimated attack date is April 11, 2026, and the listing was added to our database on April 20, 2026. No single party is currently listed as claiming the breach in our catalog, though reporting has tied the actor to the incident.
April 17, 2026: A dataset attributed to Amtrak appeared on a widely used breach notification service, listing more than 2.1 million unique accounts, according to reporting by Fox News and UpGuard.
April 29, 2026: The incident was publicly reported in detail by security researchers, with attribution to ShinyHunters and estimates that the total number of affected records could reach up to 9.4 million, a figure Amtrak has not confirmed.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, affecting an estimated 2,199,615 records
Phone numbers, affecting an estimated 974,628 records
Names, affecting an estimated 2,258,758 records
Street addresses, affecting an estimated 1,584,654 records
External reporting, including coverage from Fox News and UpGuard, also describes customer support records among the exposed data. Those reports did not indicate that passwords or payment card details were part of the leaked dataset.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of names, email addresses, phone numbers, home addresses, and support history is well suited to targeted phishing. Scammers can reference real trip details or support tickets to make messages look legitimate, which makes fake refund offers, "account problems," or payment requests far more convincing.
People whose phone numbers were exposed may receive smishing texts posing as Amtrak. Home addresses in circulation raise the risk of fraudulent letters and other mail-based scams. Because the reported dataset does not appear to include passwords, direct account takeover through this breach alone seems less likely, but attackers can still combine this information with credentials from unrelated breaches. Researchers quoted in the coverage also flagged identity theft as a general risk, since personal contact details can support fraudulent account applications.
What Should You Do If You Were Affected?
If you have traveled with Amtrak or contacted its support team, take these steps regardless of whether you receive a notice:
Be skeptical of unsolicited emails, texts, or calls that mention Amtrak, your travel history, or a support ticket. Do not click links or call numbers included in those messages. Contact Amtrak through the phone number or website listed on your own records.
Never share payment details, Social Security numbers, or account passwords in response to an unexpected message, even one that cites accurate personal information.
Turn on multi-factor authentication for your Amtrak account and the email address tied to it, and use a strong, unique password for each account.
Watch your financial accounts and credit reports for unexplained activity. You can place a free fraud alert or credit freeze with the major credit bureaus if you see anything suspicious.
Keep an eye out for a formal notification from Amtrak. If one arrives, follow its instructions and verify it against information posted on the company's official website.
