Overview
- Trenitalia disclosed on Friday that it detected a malicious intrusion in October 2025 and has on June 26 individually notified customers it could verify were affected after months of forensic analysis.
- The company says accessed information may include names, contact details, identity-document data, loyalty-card codes and ticket metadata such as route, date, time and ticket number.
- Trenitalia states that account credentials and payment card data — including card numbers, expiry dates and security codes — were not involved in the breach.
- The firm has notified the Italian data-protection authority (Garante) and CSIRT Italia and filed a criminal complaint with the Rome prosecutor, and technical and legal investigations continue.
- Consumer groups and Trenitalia warn of a higher risk of targeted phishing and fraud using travel details, and the company has opened a dedicated assistance channel while regulators may review the delay between the October intrusion and June notifications.