Site navigation

LNER Customer Data Compromised In Third-party Breach

Elizabeth Greenberg

,

lner data breach
While the nature of the breach remains uncertain, LNER has urged customers to execute caution.

One of the UK’s major train operators has been affected by a cyber incident and has confirmed that customer data has been compromised in a third-party breach.

LNER said it was made aware of “unauthorised access to files managed by a third-party supplier,” with “customer contact details and some information about previous journeys” included in the compromised files.

However, no bank, payment card or password information was affected. Still, the government-owned company that operates trains in England and Scotland urged customers to abide by solid cyber hygeine, including appropriate password management.

While the train operator said that, given the nature of the compromised information, passwords would not need to be changed, it did caution against how other information could be used in future attacks.

It urged customers to “please be cautious of unsolicited communications, especially those asking for personal information. If in doubt, do not respond.”

The company will provide further updates as their investigation continues.

“Regardless of how the attack was executed, LNER customers should take note of the advice offered by the organisation,” William Wright, CEO of Closed Door Security said.

“With personal data now in the hands of threat actors, they will be working painstakingly to monetise from it.

“Attackers will likely scour online platforms with the data they have and work to build on it so they have more detailed profiles on individuals.


Recommended reading


“They will then likely use the incident to send out phishing emails, which are designed to look like genuine communications from brands, including LNER, but are actually aimed at tricking recipients into handing out their personal or financial information.

“It is essential that online users take note of this threat and treat all email, SMS and phone calls with caution.

“Phishing isn’t confined to email these days, attackers frequently also use the phone, SMS, and WhatsApp even post services to target consumers.”

Elizabeth Greenberg

Staff Writer

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences