EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
Madison Square GardenJohn Summit
/data-breach/2026-amtrak-shinyhunters-breach
042/430

File EL-0389HighResolvedData Breach / Extortion with Data Exfiltration

Amtrak Data Breach

Also filed as ShinyHunters Amtrak Hack · Amtrak Customer Data Leak

ShinyHunters breached Amtrak, the U.S. national passenger railroad, stealing personal information of approximately 2.1 million customers including loyalty program and booking data.

  • #transportation
  • #rail
  • #pii
  • #customer-data
  • #extortion
Notoriety7/10
Event
1 Apr 2026
Disclosed
17 Apr 2026
Target
Amtrak
Actor
ShinyHunters
Scale
2.1M people
Status
Resolved

01Summary

In April 2026, ShinyHunters gained access to Amtrak's customer database and exfiltrated 2.1 million records. The stolen data included customer names, email addresses, phone numbers, and Amtrak Guest Rewards loyalty program information. Amtrak confirmed the breach in mid-April 2026. The breach was listed on Have I Been Pwned on April 17, 2026.

02Background

Amtrak is the United States' national passenger railroad service, operating over 300 trains daily across 46 states and carrying over 30 million passengers annually.

03Technical analysis

The attack followed ShinyHunters' established methodology of social engineering to compromise credentials for bulk data extraction.

Attack vector
Social engineering / Credential compromise
Attack method
Data exfiltration and extortion
Initial access
Social engineering (likely vishing)
Exfiltration
Bulk data extraction

04Threat actor

ShinyHunters is a prolific cybercriminal/extortion group.

Aliases

  • SH

Attribution sources

  • ShinyHunters leak site
  • BleepingComputer
  • Have I Been Pwned
  • Amtrak statements

05Victims and impact

Countries affected

  • United States

06Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers
  • Loyalty program data

07Financial damage

Reputational damage to a federally operated transportation service.

08Timeline

  1. 2026-04-01Approximate date of breach.
  2. 2026-04-17Breach disclosed and listed on HIBP (2.1M records).

09Reaction and fallout

Public reaction

Concern over security of federally operated transportation customer data.

Political impact

Increased scrutiny of cybersecurity practices at federally operated transportation agencies.

10Significance and legacy

Significance

Demonstrates vulnerability of federal transportation infrastructure to criminal extortion groups.

11Disclosure and media

Authentication
Amtrak confirmation and HIBP listing

Publishing organisations

  • BleepingComputer
  • Have I Been Pwned

12Related files

Related events

  • 2026-charter-communications-shinyhunters-breach

13Field notes

  1. 01Amtrak operates over 300 trains daily across 46 states.

14Resolution

Amtrak confirmed the breach and notified affected customers.

15Sources

Official documents

  • Amtrak data breach notification

References

  1. [1]BleepingComputer: Amtrak data breach coverage
  2. [2]Have I Been Pwned - Amtrak listing
Fact sheetEL-0389

Dates

Event
1 Apr 2026
Started
1 Apr 2026
Discovered
1 Apr 2026
Disclosed
17 Apr 2026
Ongoing
No

Target

Organisation
National Railroad Passenger Corporation (Amtrak)
Type
Government Corporation
Sector
Transportation / Rail
Country
United States
Gov. level
Federal

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through data extortion.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
2,100,000
Records
2,100,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Likely

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.