Site navigation

LNER Customer Data Compromised In Third-party Breach

Elizabeth Greenberg

,

lner data breach
While the nature of the breach remains uncertain, LNER has urged customers to execute caution.

One of the UK’s major train operators has been affected by a cyber incident and has confirmed that customer data has been compromised in a third-party breach.

LNER said it was made aware of “unauthorised access to files managed by a third-party supplier,” with “customer contact details and some information about previous journeys” included in the compromised files.

However, no bank, payment card or password information was affected. Still, the government-owned company that operates trains in England and Scotland urged customers to abide by solid cyber hygeine, including appropriate password management.

While the train operator said that, given the nature of the compromised information, passwords would not need to be changed, it did caution against how other information could be used in future attacks.

It urged customers to “please be cautious of unsolicited communications, especially those asking for personal information. If in doubt, do not respond.”

The company will provide further updates as their investigation continues.

“Regardless of how the attack was executed, LNER customers should take note of the advice offered by the organisation,” William Wright, CEO of Closed Door Security said.

“With personal data now in the hands of threat actors, they will be working painstakingly to monetise from it.

“Attackers will likely scour online platforms with the data they have and work to build on it so they have more detailed profiles on individuals.


Recommended reading


“They will then likely use the incident to send out phishing emails, which are designed to look like genuine communications from brands, including LNER, but are actually aimed at tricking recipients into handing out their personal or financial information.

“It is essential that online users take note of this threat and treat all email, SMS and phone calls with caution.

“Phishing isn’t confined to email these days, attackers frequently also use the phone, SMS, and WhatsApp even post services to target consumers.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data