Skip to content

Hacker attack on Trenitalia, what happened

All the details about the hacker attack on Trenitalia

 

But what happened and how was the hacking of Trenitalia discovered?

WHAT HAPPENED TO TRENITALIA

On June 26, 2026, Trenitalia sent its customers a new communication regarding a cybersecurity incident that resulted in unauthorized access to some personal data related to travel tickets. In the text, the company reports having detected the event following internal checks and attributed it to “unidentified external subjects.”

According to the communication, “to precisely identify the potentially involved subjects, it was necessary to carry out thorough technical and security analyses by our IT structures,” an activity that required time because it involved “reconstructing in detail any improper access to the data.” Only after these verifications, the text continues, was the company able to identify the affected customers and send the notification, as required by Article 34 of EU Regulation 2016/679 (GDPR) and in accordance with the guidelines of the European Data Protection Board (EDPB) no. 9/2022, version 2.0 of March 28, 2023.

TRENITALIA’S CLARIFICATIONS

Trenitalia clarifies that “no account access data, personal credentials or payment information such as card number, expiration date or security code were involved.” The categories of personal data that, if present on the IT systems in relation to the travel ticket, could have been subject to unauthorized access include personal and identifying data of the passenger and any purchaser, contact data such as email and phone number, travel data such as route, date and time of travel and ticket number, loyalty card code if associated with the ticket, the company or employer, the type of offer or service associated with the ticket and the data necessary to use it, identity document details and data related to the generation of the travel ticket.

THE FS GROUP’S REASSURANCES

In the communication, the company states that upon detecting the event, it took “all necessary measures to stop the anomaly, secure the systems and further strengthen controls.” Trenitalia declares it has already notified the incident to the Data Protection Authority and Csirt Italy, in compliance with current regulations, and has filed a complaint with the Public Prosecutor’s Office at the Rome court. In the text, the company warns affected customers of the risk of receiving “fraudulent communications or deceptive contact attempts referring to their travels,” given the type of data involved, and recommends caution towards suspicious messages requesting personal or financial data or containing unexpected links or attachments, reminding that Trenitalia never contacts customers to ask for passwords or payment data. For clarifications, the company has activated a dedicated assistance service, reachable via the “Privacy – Personal Data Management option on its webform.

Back To Top