logo

Amtrak confirms crooks are breaking into user accounts, derailing email addresses

ID: 5c881814-51be-5677-96fd-0d4420884601

STIX ID: report--5c881814-51be-5677-96fd-0d4420884601

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2024-06-19

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Amtrak Guest Rewards experienced a three-day credential-stuffing attack (May 15–18) in which attackers used usernames/passwords obtained from third-party breaches to access some user accounts. Amtrak forced password resets, changed compromised email addresses, and enabled multifactor/2FA for affected accounts; potentially exposed data includes names, contact details, DOBs, partial payment and gift card information, account numbers and travel history.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.