Data leak
London North Eastern Railway (LNER) Third-Party Vendor Breach
Primary Source βIncident Details
London North Eastern Railway (LNER), the UK train operator serving the East Coast Main Line between London King’s Cross, Edinburgh, and Aberdeen, disclosed in September 2025 that a third-party vendor had been compromised. The breach exposed customer contact details and journey information for affected LNER passengers. LNER notified affected customers and reported the incident to the ICO as required under GDPR/UK GDPR obligations.
Technical Details
- Initial Attack Vector
- An unnamed third-party vendor used by LNER was compromised, exposing customer contact details and journey information stored in the vendor's systems
Timeline
- 2025-08-15 Breach occurred
- 2025-09-25 Publicly disclosed
- 2025-09-25 Customers notified