#EURail went off the rails with its data #security incident: https://eurail.zendesk.com/hc/en-001/sections/33099464002205-Data-Security-Incident-Frequently-Asked-Questions
Personally identifiable information (name, gender, birth date, passport number, residence...) got stolen and went up for sale on the dark web.
In a recent email, EU Rail is recommending that clients take extra precaution by updating passwords and don't talk to strangers on the interwebs.
Why is EU Rail 1) storing 2) unencrypted #pii? Why can't users remove pii from their account after intended use?




