Trenitalia victim of data breach: notifications to the Guarantor and the CSIRT
Trenitalia has suffered a data breachThe company communicated the breach to its customers via email, explaining that the attack was allegedly caused by "unidentified external parties" and that, after thorough technical checks, it was possible to identify the potentially affected individuals.
According to the report, account login details, personal credentials, or payment information (card number, expiration date, or security code) were not compromised.
What data is involved?
The breach may have affected various categories of personal data:
• Personal data: name, surname, date and place of birth of the passenger and of the potential purchaser
• Contact: email address and telephone number
• Travel data: route, date, time, ticket number
• Loyalty card code, if associated with the ticket
• Employing company or entity
• Type of offer or service purchased
• Identity document details
• Technical data related to the generation of the travel ticket
Notification to the Guarantor and the CSIRT
Trenitalia has specified that it has immediately adopted the necessary measures to contain the incident and that it has notified the incident to Guarantor for the protection of personal data and CSIRT Italy, as required by law. A complaint has also been filed with the Public Prosecutor's Office at the Court of Rome.
The risk of phishing
Trenitalia warns that there is a risk that customers may receive fraudulent messages or attempted scams. Phishing that relate to your travel. The company urges you to be wary of suspicious emails, text messages, or phone calls and not to provide personal or financial information. Trenitalia reminds you that it will never contact customers to request passwords or payment information.
For further information, please contact us via the "Privacy - Personal Data Management" web form.
Find out more from Napolike.com
Subscribe to receive the latest articles sent to your email.