• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

LNER customer data loss

Status
Not open for further replies.

jthjth

Member
Joined
10 Apr 2015
Messages
382
Major UK player cagey on specifics but latest attack follows string blamed on 'third party' suppliers

One of the UK's largest rail operators, LNER, is the latest organization to spill user data via a third-party data breach.

It confirmed the incident on Wednesday, saying customer contact details and "some information about previous journeys" was accessed at a third-party supplier.

London North Eastern Railway (LNER) did not name the third party responsible for the intrusion, but assured that whichever company it was, it does not store details such as bank accounts, payment cards, or passwords....
Unfortunately another data loss. It’s a bit of a plague at the moment.
 
Last edited:
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Halwynd

Member
Joined
11 Sep 2021
Messages
554
Location
North West
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.

The Co-op allowed my data to be breached and I no longer shop with them. I now no longer trust LNER and the same will apply.
 

dk1

Veteran Member
Joined
2 Oct 2009
Messages
19,789
Location
East Anglia
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.

The Co-op allowed my data to be breached and I no longer shop with them. I now no longer trust LNER and the same will apply.
its unfortunate these things happen but if i followed that rule I wouldn’t be able to shop at M&S and the thought of that is simply inconceivable. Also I’d spite the nose off my face by not using LNER and Coop is my nearest local shop.
 

whoosh

Established Member
Joined
3 Sep 2008
Messages
1,884
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.

The Co-op allowed my data to be breached and I no longer shop with them. I now no longer trust LNER and the same will apply.
Great idea. That will mean that when these companies are weighing up whether to pay organised criminal hackers their ransom demands, a potential fine will form part of that decision making process:

Loss of confidence by customers.
Loss of systems.
[Fine]

Or,
Paying the ransom.

A fine just makes it more likely that organised criminals will make more money more often, surely?
 

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
Great idea. That will mean that when these companies are weighing up whether to pay organised criminal hackers their ransom demands, a potential fine will form part of that decision making process:

Loss of confidence by customers.
Loss of systems.
[Fine]

Or,
Paying the ransom.

A fine just makes it more likely that organised criminals will make more money more often, surely?
no, "or", it'll always be "and" - because whether or not they pay the ransom, they'd still be legally obliged to report the breach so are likely to be fined anyway.

== Doublepost prevention - post automatically merged: ==

It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.
that's already an option - just like any other kind of punishment. And it happens, e.g. this company was fined ~£3m (~£40 per item of data) for a data breach: https://ico.org.uk/action-weve-taken/enforcement/2025/03/advanced-computer-software-group-limited/, and the MOD were fined ~£1300 per email address leaked in this instance: https://ico.org.uk/action-weve-taken/enforcement/ministry-of-defence-1/
 
Last edited:

Halwynd

Member
Joined
11 Sep 2021
Messages
554
Location
North West
It would be interesting to find out who the third party is. The organisations prosecuting fare evasion spring to mind, and would Seatfrog have access I wonder? I guess it will all come out in the wash.

As an aside, it was announced today that the M&S IT chief is leaving her position after just a year in the job. She had pointed to shortcomings at M&S, warning that the company needed to invest more in its IT capability. At an investor conference last November she said there had been a “decade of underinvestment” in IT at M&S, adding that the business did not have enough in-house IT experts. She said there was a “critical internal knowledge gap”.
 

Vexed

Member
Joined
12 Jan 2020
Messages
637
Location
Herts / Hants
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.
Indeed. I'm potentially affected by the Online SCR breach from when I worked for my school while in Sixth Form - it's pretty serious (name, date of birth, address/contact details, NI numbers, passport numbers, drivers licence numbers etc if they were held) - and all I have is an email saying employee data "may have been compromised for some individuals" which manages to use 7 words to say nothing!

I guess I'm probably impacted by the LNER breach as well, but nowhere near as serious as the above.

It would be interesting to find out who the third party is. The organisations prosecuting fare evasion spring to mind, and would Seatfrog have access I wonder? I guess it will all come out in the wash.
Maybe Silerrail as they run the booking engine LNER uses.
 

Watershed

Veteran Member
Associate Staff
Senior Fares Advisor
Joined
26 Sep 2020
Messages
16,572
Location
UK
Based on the information they've given, my guess would be the supplier of their journey alert SMS functionality.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,615
Location
Gwynedd
The Co-op allowed my data to be breached and I no longer shop with them. I now no longer trust LNER and the same will apply.
I do make shopping decisions based on things like this to an extent, but if I avoided every retailer which had suffered a data breach, I'd probably starve.

Co-op, M&S, Tesco, Asda, Sainsbury's have all had data breaches in the past decade.
 

Halwynd

Member
Joined
11 Sep 2021
Messages
554
Location
North West
I do make shopping decisions based on things like this to an extent, but if I avoided every retailer which had suffered a data breach, I'd probably starve.

Co-op, M&S, Tesco, Asda, Sainsbury's have all had data breaches in the past decade.

You're right - I was pretty infuriated when I read about this earlier and, I admit, perhaps less than pragmatic, but only because I've spent time working in the victim arena and have seen first hand the devastating impact fraud can have on their lives. Companies such as Co-op, M&S and LNER take data security seriously, just not seriously enough, and where customer losses are remedied it's always the bank that has to pay, never the retailers who allow the problem to occur in the first place.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,615
Location
Gwynedd
You're right - I was pretty infuriated when I read about this earlier and, I admit, less than pragmatic, but only because I've spent time working in the victim arena and have seen first hand the devastating impact fraud can have on their lives. Companies such as Co-op, M&S and LNER take data security seriously, just not seriously enough, and where customer losses are remedied it's always the bank that has to pay, never the retailers who allow the problem to occur in the first place.
I think what happens in many of these cases is the data controller puts an agreement in place with their supplier, a data processor, and somewhat leaves them to it. At best they might check for some sort of accreditation like ISO 27001 or Cyber Essentials at procurement time, then it's like a 'fire and forget' where they just assume the processor is keeping good tabs on their information security. Then the supplier suffers a breach and CIOs/CISOs at the data controller get a kicking and the PR department tries to word the public messaging to emphasise the supplier fault in the situation.

I am sure a lot of these companies change their data processor monitoring policies in response to breaches, but it's a bit 'too little too late'.
 

TUC

Established Member
Joined
11 Nov 2010
Messages
5,021
Somehow I don't feel terribly worried about someone knowing I travelled between Leeds and Halifax.
 

Megafuss

Member
Joined
5 May 2018
Messages
884
Location
Spalding
It would be interesting to find out who the third party is. The organisations prosecuting fare evasion spring to mind, and would Seatfrog have access I wonder? I guess it will all come out in the wash.

As an aside, it was announced today that the M&S IT chief is leaving her position after just a year in the job. She had pointed to shortcomings at M&S, warning that the company needed to invest more in its IT capability. At an investor conference last November she said there had been a “decade of underinvestment” in IT at M&S, adding that the business did not have enough in-house IT experts. She said there was a “critical internal knowledge gap”.
Is it possibly linked to the software used for Auto Delay Repay?
 

skyhigh

Established Member
Joined
14 Sep 2014
Messages
6,842
Somehow I don't feel terribly worried about someone knowing I travelled between Leeds and Halifax.
You might not, but it's easy to see why it could be a problem for someone more vulnerable.

Contact details and journey details could create quite a convincing scam for someone unaware.

A direct phone call, along the lines of "Hello, is that Mr Joe Bloggs? It's x from LNER calling, our records show you were on the delayed 11.15 from Leeds to London on Tuesday. Have you claimed a refund on your ticket? No? Oh don't worry, I can sort that for you now if you just provide me with the full card number of the card you paid with..." etc
 

dk1

Veteran Member
Joined
2 Oct 2009
Messages
19,789
Location
East Anglia
Which Co-op is it though?

They generally use the same branding (except Scotmid or Nisa), but there are dozens of different Co-ops.
We’ve got two in the village both different and a third on Norwich station which is different again. Years ago I think some were Ipswich, others Peterborough Co-op.
 

J663738

Member
Joined
20 May 2025
Messages
339
I think most companies will have their data breached in one way or another for now on.....
LNER are just the latest, at least their trains are still running, unlike the JLR productions lines.

Sadly I have a spread sheet with about a hundred different logins and passwords, plus about twenty different e-mail accounts.
And they said technology would make life simpler?

== Doublepost prevention - post automatically merged: ==

I have various e-mail accounts setup just for specific retailers (e.g. Amazon) so I know if I am being scammed.

== Doublepost prevention - post automatically merged: ==

The thing I find strange is being told to have a very hard to crack password, that contains various symbols and characters etc.
But I am not sure who's benefit this is for, as most sites if you try a numbers of times and fail, you are locked out and have to reset anyway.
Most passwords and logins are stolen via the companies network, so what is the point in making it overly complicated, better to have lots of unique simple ones.
 
Last edited:

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
Sadly I have a spread sheet with about a hundred different logins and passwords, plus about twenty different e-mail accounts.
that's what a password manager is meant to prevent the need for...

== Doublepost prevention - post automatically merged: ==

better to have lots of unique simple ones.
obligatory reminder of this very relevant XKCD comic: https://xkcd.com/936/
 

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
Most I have come across are online is some way or another and I don't trust them!
I do use Lastpass (which is an online one: primarily because it syncs across mobile and desktop devices, and because the organisation I work for provides Premium access for all staff), but my colleagues who don't want to use Lastpass, and want to use an offline alternative, tend to use KeePass (https://keepass.info/) which has been around a pretty long time and tends to get positive comments from those who are security-conscious
 

MrJeeves

Established Member
Associate Staff
Senior Fares Advisor
Joined
28 Aug 2015
Messages
4,608
Location
Burgess Hill
Most I have come across are online is some way or another and I don't trust them!
I'd trust them more than a spreadsheet stored locally on a machine that might suffer from data loss any moment.

I used Google's own password manager for years without issue until switching to 1Password (paid) a few months ago.
 

J663738

Member
Joined
20 May 2025
Messages
339
I'd trust them more than a spreadsheet stored locally on a machine that might suffer from data loss any moment.
Are you saying someone is going to hack into to my laptop running linux and break into to an encrypted file? I doubt it, more likely they will hack in to somewhere where millions of passwords are stored for the same effort and a lot more gain.
 

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
Are you saying someone is going to hack into to my laptop running linux and break into to an encrypted file? I doubt it, more likely they will hack in to somewhere where millions of passwords are stored for the same effort and a lot more gain.
no - hard drives fail.

Estimates are ~2% of hard drives fail every year, so one way of interpreting that is that you have a 1 in 50 chance of your hard drive failing in any given year, although this gets more likely with the age of the hard drive. There's a reason that RAID storage is a thing. In the data centres I know about (professionally), hard drives are treated as consumables that are changed somewhere in the data centre on a daily basis

And then if you're storing your file on any kind of cloud storage, why do you trust that any more than an online password manager?
 
Last edited:

styles

Established Member
Joined
7 Dec 2014
Messages
4,615
Location
Gwynedd
I do use Lastpass (which is an online one: primarily because it syncs across mobile and desktop devices, and because the organisation I work for provides Premium access for all staff), but my colleagues who don't want to use Lastpass, and want to use an offline alternative, tend to use KeePass (https://keepass.info/) which has been around a pretty long time and tends to get positive comments from those who are security-conscious
In fairness, there are concerns about LastPass after their breach a couple of years ago: https://blog.lastpass.com/posts/notice-of-recent-security-incident. Yes the password files were/are securely-encrypted, but if somebody had a weak master password, their passwords are at risk.

It was particularly frustrating to read at the time because it sounds like LastPass were failing some pretty basic information security policies which led to this event. You then have to wonder, if they can't get the basics right, can they get the more complicated stuff right?
 

Halwynd

Member
Joined
11 Sep 2021
Messages
554
Location
North West
You might not, but it's easy to see why it could be a problem for someone more vulnerable.

Contact details and journey details could create quite a convincing scam for someone unaware.

A direct phone call, along the lines of "Hello, is that Mr Joe Bloggs? It's x from LNER calling, our records show you were on the delayed 11.15 from Leeds to London on Tuesday. Have you claimed a refund on your ticket? No? Oh don't worry, I can sort that for you now if you just provide me with the full card number of the card you paid with..." etc

Exactly... and the example you give is a good one. As we know, data is also used for social profiling fraud and in my experience victims don't have to be vulnerable - they can be young or old, well educated or less well educated, the wealthy and the less wealthy. Some scams are obvious, but others can be very sophisticated.

At least M&S and the Co-op apologised, LNER can't even be bothered to say sorry.
 

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
At least M&S and the Co-op apologised, LNER can't even be bothered to say sorry.
I think the key difference is that the breach suffered by M&S and Coop appeared to be on their self-hosted infrastructure - LNER have made it clear it's on third-party infrastructure, and I'm sure that LNER's legal team have approved the comms; they might be worried that saying "sorry" would automatically imply blame / acknowledgement that it's their fault
 
Status
Not open for further replies.

Top