One of the UK’s major train operators has been affected by a cyber incident and has confirmed that customer data has been compromised in a third-party breach.
LNER said it was made aware of “unauthorised access to files managed by a third-party supplier,” with “customer contact details and some information about previous journeys” included in the compromised files.
However, no bank, payment card or password information was affected. Still, the government-owned company that operates trains in England and Scotland urged customers to abide by solid cyber hygeine, including appropriate password management.
While the train operator said that, given the nature of the compromised information, passwords would not need to be changed, it did caution against how other information could be used in future attacks.
It urged customers to “please be cautious of unsolicited communications, especially those asking for personal information. If in doubt, do not respond.”
The company will provide further updates as their investigation continues.
“Regardless of how the attack was executed, LNER customers should take note of the advice offered by the organisation,” William Wright, CEO of Closed Door Security said.
“With personal data now in the hands of threat actors, they will be working painstakingly to monetise from it.
“Attackers will likely scour online platforms with the data they have and work to build on it so they have more detailed profiles on individuals.
Recommended reading
- Jaguar Land Rover Cyber-attack Disrupting Production and Sales
- M&S Hackers Take Credit for Jaguar Land Rover Cyber-attack
- How Scattered Spider’s Web Brought UK Retail to its Knees
“They will then likely use the incident to send out phishing emails, which are designed to look like genuine communications from brands, including LNER, but are actually aimed at tricking recipients into handing out their personal or financial information.
“It is essential that online users take note of this threat and treat all email, SMS and phone calls with caution.
“Phishing isn’t confined to email these days, attackers frequently also use the phone, SMS, and WhatsApp even post services to target consumers.”





