• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

LNER customer data loss

Status
Not open for further replies.

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
I think the Data Protection Registrar (apparently now called the Information Commissioner) would have more credibility if they actually used their resources to identify and try to block those who perpetrate these raids.
...
That would be ideal, unfortunately:
  • It's well beyond their budget, capabilities and remit. Other organisations exist for that purpose, including the security services and specialist police departments.
  • Identification typically leads to dead ends - many of the people and groups involved when they can be identified are beyond our jurisdiction or extradition
  • Blocking is essentially impossible since these people and groups use hijacked intermediary devices from around the world, i.e. the ever growing and changing "botnets"; so blocking individual IP addresses, or even entire countries has no real effect.
This is essentially why the only really effective tool we have is to persuade, assist and coerce if necessary domestic companies to improve their security. They don't have to be impenetrable (which is impossible), they just need to not be the low-hanging fruit.

At the moment, as far as the powers of this nation is concerned, many of the attackers are largely like bad weather or high tides; an unstoppable force of nature we can only prepare for and mitigate against as best we can. The UK can no more catch and punish them than we could a hurricane.

Of course, there is some domestic involvement which is sometimes detected and punished, and some in countries we can extradite from, but really that does not make a significant impact on the overall attack situation.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

800Travel

Member
Joined
3 Nov 2023
Messages
657
Location
UK
To use a very obvious counter-example, Railforums doesn't require a separate physical token or biometric for us to login (Although the site does offer the option of 2-step verification for those who wish it). So the logic of your comment would be that railforums is clearly negligent! Do you really believe that?

To be clear, I don't believe that at all: Railforums uses passwords - which (provided properly implemented) is a perfectly appropriate level of security for a non-profit-making group of volunteers providing a free service where you just couldn't justify the expense of buying in additional security - and I doubt most people would be interested in the extra hassle of doing 2-step verification just to login to read comments on a public forum. FWIW I volunteer for a similar enthusiast group for which people need to login to a website, and I'm pretty sure if we were required to use biometrics, we'd simply end up having to close down because of not being able to afford the expense. You can't just assume that any organization that only uses passwords is 'clearly negligent' - it's going to be very dependant on the context/nature of the services/etc.

Of course if it's a large company that has much more resources and is dealing with much more sensitive data - the most obvious example being a bank - then you would expect far greater security. But then, for something like a bank, most people are willing to put up with it being somewhat harder to login because they realise the dangers of their account being hacked are so huge.
Thank you for flagging re 2FA - I didn't know this was a feature on the forum so have now registered.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,443
Location
Isle of Man
I think the Data Protection Registrar (apparently now called the Information Commissioner) would have more credibility if they actually used their resources to identify and try to block those who perpetrate these raids. instead they take the easy (and lucrative) way out by fining substantially the victim organisations
Identifying those committing the crime is a matter for the police. In the case of the M&S and Co-Op issues my understanding is that they're well on the way to identifying them.

The Information Commissioner will- rightly- fine companies that haven't taken all reasonable steps to secure their data. Companies which have taken all reasonable steps will not be fined. I think that is entirely reasonable. We entrust our data to these companies and we expect them to look after the data properly.
In addition to having to issue probably all of their technical and operational, and a good proportion of their customer-facing staff with biometric tokens, they would have to contend with those staff being unable to work for protracted periods whenever they lost their token.
You can buy these systems pretty much off the shelf from companies like Okta. They're not difficult to implement.

To access the case management system in my last job we either had to use the Okta authentication app on our mobile phone or we had to use the dongle/widget which we held in our office. This was in addition to our username and password. It's by no means foolproof, and would still be susceptible to determined spear-phishing, but it adds another layer of security. It means that a leak of the username and passwords is useless on its own.
 

87 027

Member
Joined
1 Sep 2010
Messages
735
Location
London
You can buy these systems pretty much off the shelf from companies like Okta. They're not difficult to implement.

To access the case management system in my last job we either had to use the Okta authentication app on our mobile phone or we had to use the dongle/widget which we held in our office.
Ahem...


Okta admits hackers accessed data on all customers during recent breach

Cyber security and resilience is a serious problem and we shouldn't be lulled into a false sense of security that solutions are easy
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,443
Location
Isle of Man
Cyber security and resilience is a serious problem and we shouldn't be lulled into a false sense of security that solutions are easy
I completely agree. But cyber security is really the Swiss cheese method, and the more slices of cheese you put in the better it is.

My point is that even smaller companies can get 2FA in relatively easily.

As I said further up, the hackers only have to get lucky once.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,615
Location
Gwynedd
I feel this may have drifted away from the LNER data loss quite a while back. Perhaps worth a separate thread in general discussion?
 

njwe3

New Member
Joined
21 Sep 2025
Messages
1
Location
lodon
Here's a concrete example of a provisional decision against a data processor which leaked NHS data. Note that there is no mention of so much as a reprimand against the NHS. The ICO has found against the NHS in cases where NHS Staff have been at fault.

Banks are governed by specific legislation, and US law may have taken precedence.

Also, responsibility for accuracy of personal data and for not agreeing to it being sent to a country where inadequate data protection exists always remains with the entity collecting the data - sending inaccurate data to the Philippines would break UK law twice over.
The provisional £6.09m fine against Advanced highlights the serious consequences of failing to protect personal data, especially when NHS information is involved. While the NHS was not directly reprimanded here, the ICO has previously acted where NHS staff pay and data responsibilities intersect with staff conduct. Ultimately, accountability remains with the data controller, ensuring personal information is accurate and not transferred to countries with inadequate protection like the Philippines.
 

londonbridge

Established Member
Joined
30 Jun 2010
Messages
1,867
I’ve just had an email from LNER, specifically my name and email address was among the data accessed in the hack. They say no payment card details, passwords or my LNER account info was involved, and that I should be wary of scam and/or phishing emails.
 

800Travel

Member
Joined
3 Nov 2023
Messages
657
Location
UK
I’ve just had an email from LNER, specifically my name and email address was among the data accessed in the hack. They say no payment card details, passwords or my LNER account info was involved, and that I should be wary of scam and/or phishing emails.
It's weird they've only just emailed you, wonder if they've discovered more was accessed than they thought
 

Cach17

Member
Joined
13 Jul 2023
Messages
196
Location
Kent
Maybe they could bring back the cashback offer to say sorry....
They'll probably do that if the implementation of their December timetable change goes horribly wrong! (thinking back to Northern, TPE and GTR in May 2018)
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,615
Location
Gwynedd
I've received it just this minute also:

LNER said:
Dear XXXX,

We are getting in touch from the LNER Data Protection Team to tell you that a personal data breach has taken place.

What happened

On 8 September 2025 we were told that one of our suppliers, who manages our customer communication database, had suffered a security incident. A third-party gained unauthorised access to the supplier’s networks and in the process gained access to customer data.

As a result of our investigation of the breach so far, we have concluded that the data included some personal information, specifically your name and email address.

No payment card details, passwords or your LNER account information were involved. Our ticketing systems remain safe, and you can continue to buy tickets from LNER as normal.

Because your name and email address were affected, it’s possible you will receive phishing or scam messages.

What we're doing

We are continuing to work closely with our supplier, who has engaged independent security experts, to put enhanced security controls in place to minimise the risk of this happening again. We have also taken the following measures to address the breach:
  1. Reported the incident to the Information Commissioner’s Office on 9 September 2025
  2. Notified the National Cyber Security Centre (NCSC), British Transport Police (BTP) and the Department for Transport;
  3. Paused certain communication channels temporarily as a precaution.
What you should do
  1. Remain vigilant against phishing or scam attempts, including unexpected communications asking for personal or financial information.
  2. Don’t click on links or download attachments in suspicious emails.
  3. Be aware that phishing attempts may appear to come from LNER when they have not. Emails sent from LNER will end in @lner.co.uk or @email.lner.co.uk; threat actors may try to imitate this with similar characters, for example, using the number 1 instead of the letter L. You can contact us at datainfo@lner.co.uk if you are in doubt about whether an email or message comes from LNER.
Although we understand that password information has not been affected, we also suggest that you maintain a secure password and change your password regularly. Remember that we will never ask you to provide us with your password.

Contact us

We have set up a dedicated mailbox - datainfo@lner.co.uk - for questions about this incident. It goes directly to our Data Protection Officer, John.


Yours sincerely,
LNER Data Protection Team

Funnily enough, I had my first piece of spam email to this email address a few days ago. I wonder if it's related. I forgot to use plus aliasing when signing up with LNER so can't say for sure it came from this breach, but it's the only breach of that address I'm aware of.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,615
Location
Gwynedd
Did LNER text 61016 :?: [sarcasm]
I'm mildly curious as to how often the BTP are involved with cyber security incidents, and more importantly how competent they are?
I've honestly got non idea what BTP could do with this report. At best I think they'd hand it off to NCSC or the ICO.

Is it BTP's remit to investigate cybercrime against TOCs? I'd be surprised!
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,498
Location
Warks
I also received the email:

On 8 September 2025 we were told that one of our suppliers, who manages our customer communication database, had suffered a security incident. A third-party gained unauthorised access to the supplier’s networks and in the process gained access to customer data.

However, 5 months ago, I was told:

Dear Adam,

We haven't heard from you in a while so we're going to stop sending marketing emails, SMS and push notifications to you. Your LNER account will still be active, you’ll just no longer receive news about ticket deals, seat sales or any other offers.

At this point, I'd like to understand which supplier this was - and, if it was a marketing company, why the personal data hadn't been removed when they emailed me back in May.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,615
Location
Gwynedd
I also received the email:



However, 5 months ago, I was told:



At this point, I'd like to understand which supplier this was - and, if it was a marketing company, why the personal data hadn't been removed when they emailed me back in May.
Does 'customer communications database' necessarily mean a company administering 'marketing emails'? As in, could it have been a database for e.g. live travel alerts?

If it was a marketing database, the other questions would be for example do they retain email addresses of people who have opted out under some other lawful basis, did the hackers gain access to an event log of messages sent and that's where they derived their data from, etc.
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,498
Location
Warks
Does 'customer communications database' necessarily mean a company administering 'marketing emails'? As in, could it have been a database for e.g. live travel alerts?

If it was a marketing database, the other questions would be for example do they retain email addresses of people who have opted out under some other lawful basis, did the hackers gain access to an event log of messages sent and that's where they derived their data from, etc.
That's a fair point, but then it's so vague as to be useless, really!
 

YorksLad12

Established Member
Joined
5 Feb 2020
Messages
2,697
Location
Leeds
I haven't received an email. Nobody loves me, not even LNER's hackers...

I only use the site to buy tickets, though they do send me emails from the loyalty scheme. I wonder if that makes a difference? Live travel alerts come via text, I thought?
 

Sonic1234

Member
Joined
25 Apr 2021
Messages
785
Location
Croydon
I've honestly got non idea what BTP could do with this report. At best I think they'd hand it off to NCSC or the ICO.
It's to give people confidence they're doing all they can: look we've even informed the police - and it's the BTP, you know, the railway police. Absolutely no cover up here!
 

philjo

Established Member
Joined
9 Jun 2009
Messages
3,010
I haven't received an email. Nobody loves me, not even LNER's hackers...

I only use the site to buy tickets, though they do send me emails from the loyalty scheme. I wonder if that makes a difference? Live travel alerts come via text, I thought?
I thought the same but I found one this evening lurking in my spam folder.
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,067
Location
Redcar
Yeah also landed for me this afternoon. I assume it's taken them this long to work out who they need to contact rather than them having contacted a load of people when it first happened and now finding a bunch more people they need to contact!
 

joncombe

Member
Joined
6 Nov 2016
Messages
868
I also got the same email today which states they were aware of the breach on the 8th September. It is over a month since then and they thought to tell me now? (I had seen this thread but assumed as I hadn't been notified I wasn't impacting, I guess not). According to the GDPR they are obliged to notify customers whose data is stolen without "undue delay" (see https://ico.org.uk/for-organisation...l-data-breach/personal-data-breaches-a-guide/). Over a month hardly seems to be avoiding undue delay. I don't get the feeling they are taking this as seriously as they should be.
 

Joe Paxton

Established Member
Joined
12 Jan 2017
Messages
2,958
I've honestly got non idea what BTP could do with this report. At best I think they'd hand it off to NCSC or the ICO.

Is it BTP's remit to investigate cybercrime against TOCs? I'd be surprised!

BTP does have a 'Cyber Crime Unit'. Here's a 2022 RailStaff (industry publication) interview with a DC in said unit:
www.railstaff.co.uk/2022/05/06/expert-commentary-dc-richard-gentle-cyber-crime-unit-btp/
Hi Matt, thanks for having me. BTP don’t just police the railway by offering visible uniform presence – we also have a whole host of crime departments including a Cyber Crime Unit just like any other police force. We have four working pillars that we call the ‘Four Ps’. These are: Protect, Prevent, Pursue and Prepare.

The Protect strand is effectively cybercrime awareness and crime prevention, while the Prevent strand is the ability to identify young individuals who commit cybercrime offences and offer them alternative paths within the commercial world to steer them away from hacking and committing cybercrime....
 
Last edited by a moderator:
Status
Not open for further replies.

Top