An email with a bureaucratic subject, one of those that seem written specifically to make you want to close them after three lines, is currently arriving at several Trenitalia customers. Inside, however, there is very concrete news: a hacker attack on Trenitalia led to unauthorized access to some personal data linked to travel tickets. According to what the company communicated to the passengers concerned, the accident was caused by “unidentified external subjects”.
The violation may have concerned name, surname, date and place of birth of the passenger and any ticket purchaser, as well as email address, telephone number, route, date and time of the journey, ticket number, loyalty card code, identity document details, employer and technical data linked to the generation of the ticket, when present in the systems associated with the journey. However, according to Trenitalia, account login data, personal credentials and payment informationthen card numbers, expiration dates and security codes. The company said it immediately activated all necessary security measures.
The risk now is targeted scams
The problem now moves from the violation to the possible second wave: fraudulent emails, SMS or phone calls constructed using real travel information. A message mentioning a real route or a real purchased ticket can seem much more credible than the usual phishing attempt. For this reason, it is best to avoid links received via email or SMS, enter only from official Trenitalia channels and not communicate passwords, codes, bank details or documents in response to unexpected messages.
Trenitalia announced that it had adopted measures to contain the incident, notifying the Guarantor for the protection of personal data and CSIRT Italy of the incident, and submitting a complaint to the Rome Prosecutor’s Office. In case of doubts, the most prudent reference remains the official privacy channel indicated by Trenitalia, also through the Data Protection Officer who can be reached from the Personal Data Protection page.