Particle.news
Download on the App Store

Trenitalia Says Hack Exposed Some Passengers’ Ticket and ID Data

Exposed ticket and identity details could enable targeted phishing, prompting regulator notification and a prosecutor complaint.

Overview

  • Trenitalia disclosed on Friday that it detected a malicious intrusion in October 2025 and has on June 26 individually notified customers it could verify were affected after months of forensic analysis.
  • The company says accessed information may include names, contact details, identity-document data, loyalty-card codes and ticket metadata such as route, date, time and ticket number.
  • Trenitalia states that account credentials and payment card data — including card numbers, expiry dates and security codes — were not involved in the breach.
  • The firm has notified the Italian data-protection authority (Garante) and CSIRT Italia and filed a criminal complaint with the Rome prosecutor, and technical and legal investigations continue.
  • Consumer groups and Trenitalia warn of a higher risk of targeted phishing and fraud using travel details, and the company has opened a dedicated assistance channel while regulators may review the delay between the October intrusion and June notifications.