Hackers place skimming device on website and customers suffer data breach


In April 2018, the overseas train travel company disclosed it had suffered a three-month data breach from November 2017 to mid-February 2018. The data breach was caused by hackers installing skimming software on the company's website.

The hackers were believed to have captured customers’ name, gender, address, telephone number, email address, username, password, credit card numbers, expiration dates and CVV codes.

Given the type of information the hackers stole about the customers which left them particularly exposed to identity theft and financial fraud made the company's 10 week delay between event discovery and event notification particularly disappointing.


Courtenay Brammar

Experienced global enterprise risk and governance professional. Previously Vice President at Morgan Stanley, Deloitte Risk Advisory practitioner and PRMIA steering committee member in both London and New York.

Additional services

We offer a range of cost-effective, fixed-price training programmes and consultant services derived from the unique insights gained from all our case study data.

If you'd rather we did the heavy lifting in developing a cyber incident response plan or lessons learnt training for your organisation underpined by our unique insight into the challenges faced and strategies implemented by organisations countering today's cyber security threats then please contact us here.


  • Rail Europe North America
  • Rail Europe North America, Inc.

We've done the analysis so you can make the decisions

When purchasing a minimum of 5 Case Studies
$699.99 if buying less than 5.

  • Detailed cause & effect analysis
  • Lessons learnt catalogued
  • Preventive controls extracted
Add to Cart
Heads up! Want to try before you buy? You can download our FREE demo case study here