01Summary
In April 2026, ShinyHunters gained access to Amtrak's customer database and exfiltrated 2.1 million records. The stolen data included customer names, email addresses, phone numbers, and Amtrak Guest Rewards loyalty program information. Amtrak confirmed the breach in mid-April 2026. The breach was listed on Have I Been Pwned on April 17, 2026.
02Background
Amtrak is the United States' national passenger railroad service, operating over 300 trains daily across 46 states and carrying over 30 million passengers annually.
03Technical analysis
The attack followed ShinyHunters' established methodology of social engineering to compromise credentials for bulk data extraction.
- Attack vector
- Social engineering / Credential compromise
- Attack method
- Data exfiltration and extortion
- Initial access
- Social engineering (likely vishing)
- Exfiltration
- Bulk data extraction
04Threat actor
ShinyHunters is a prolific cybercriminal/extortion group.
Aliases
- SH
Attribution sources
- ShinyHunters leak site
- BleepingComputer
- Have I Been Pwned
- Amtrak statements
05Victims and impact
Countries affected
- United States
06Data exposed
Data types
- PII
- Names
- Email addresses
- Phone numbers
- Loyalty program data
07Financial damage
Reputational damage to a federally operated transportation service.
08Timeline
- 2026-04-01Approximate date of breach.
- 2026-04-17Breach disclosed and listed on HIBP (2.1M records).
09Reaction and fallout
Public reaction
Concern over security of federally operated transportation customer data.
Political impact
Increased scrutiny of cybersecurity practices at federally operated transportation agencies.
10Significance and legacy
Significance
Demonstrates vulnerability of federal transportation infrastructure to criminal extortion groups.
11Disclosure and media
- Authentication
- Amtrak confirmation and HIBP listing
Publishing organisations
- BleepingComputer
- Have I Been Pwned
13Field notes
- 01Amtrak operates over 300 trains daily across 46 states.
14Resolution
Amtrak confirmed the breach and notified affected customers.
15Sources
Official documents
- Amtrak data breach notification
References
- [1]BleepingComputer: Amtrak data breach coverage
- [2]Have I Been Pwned - Amtrak listing









