Amtrak A.I CyberSecurity Scoring
Amtrak
Company Information
Website:http://www.amtrak.com
Employees number:13,811
Number of followers:194,095
NAICS:482
Industry Type:Rail Transportation
Homepage:amtrak.com
Amtrak Risk Score (AI oriented)
Between 0 and 549
AmtrakRail Transportation
Updated:
27/07/2026
27/07/2026
424/1000
Critical
C
Amtrak Global Score (TPRM)
xxxx
AmtrakRail Transportation
Score locked

AmtrakCritical
Current Score
424C (CRITICAL)
01000
5 incidents
-154.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
429
JULY 2026
419
JUNE 2026
416
MAY 2026
404
APRIL 2026
476
Breach
01 Apr 2026 • Amtrak
Amtrak: Have I Been Pwned’s Post
Amtrak Data Breach Exposes Over 2 Million Email Addresses in ShinyHunters Attack
397
CRITICAL-79
AMT1776407118
Amtrak Data Breach Exposes Over 2 Million Email Addresses in ShinyHunters Attack
Earlier this month, U.S. rail operator Amtrak fell victim to a data breach attributed to the cybercriminal group ShinyHunters, with the compromised data surfacing this week. The exposed dataset includes over 2 million email addresses, along with names, physical addresses, and customer support ticket details.
Approximately 80% of the leaked email addresses were already indexed in LinkedIn’s database, suggesting prior exposure in other breaches. The incident highlights the risks of overlapping personal data across platforms, as threat actors increasingly exploit aggregated information for targeted attacks.
ShinyHunters, known for large-scale data theft and leaks, has previously targeted organizations across sectors, selling or distributing stolen records on underground forums. The breach underscores the persistent threat posed by cybercriminal groups specializing in credential harvesting and identity-related fraud.
No official statement from Amtrak regarding the breach’s impact or mitigation efforts has been released at this time. The incident adds to a growing list of high-profile breaches in 2024, reinforcing concerns over data security in critical infrastructure and service providers.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
746
Breach
01 Mar 2026 • Amtrak
Betterment, Substack, ADT, Amtrak, Hallmark, CarGurus, Panera Bread and McGraw Hill: Sextortion scammers are exploiting ShinyHunters data leaks
Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme
471
CRITICAL-275
MCGSUBAMTADTHALPANCARBET1785169886
Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme
Cybercriminals are leveraging email addresses from past ShinyHunters data breaches to lend false credibility to a new wave of sextortion scams, demanding $2,000 in Bitcoin from victims. The campaign, reported by BleepingComputer, targets individuals whose personal data was exposed in breaches of companies like Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill, as well as those affected by the Canvas data breach at a California community college.
The scam emails falsely claim to be from ShinyHunters, alleging that the group has compromised victims’ devices, recorded explicit content via webcams, and threatens to leak the footage unless payment is made within 48 hours. A sample email includes a Bitcoin wallet address currently showing no transaction activity and falsely asserts access to browsing history, contacts, and other sensitive data.
Despite the threats, no evidence supports the claims. ShinyHunters has denied involvement, and security experts confirm the emails are bluffs, relying on psychological manipulation rather than actual malware or recordings. The scammers likely obtained the email lists from publicly leaked data after ShinyHunters’ failed extortion attempts.
The $2,000 demand marks an increase from typical sextortion scams, possibly indicating the scammers acquired the data through purchase or direct download. While the emails vary in sophistication some appearing AI-polished they uniformly lack verifiable proof. Security researchers emphasize that responding to such emails can confirm an active account, leading to further targeting.
Victims are advised to ignore the threats, avoid engaging with the scammers, and report the emails as spam. If the message includes a previously used password, users should change it immediately and enable two-factor authentication (2FA). The campaign underscores how leaked data continues to fuel cybercrime, even when the original breach has been addressed.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
746
JANUARY 2026
745
DECEMBER 2025
743
NOVEMBER 2025
744
Breach
28 Nov 2025 • Amtrak
23andMe Nets Approval for Bankruptcy Plan With Data Breach Deals
23andMe Data Breach and Bankruptcy Settlement
634
CRITICAL-110
23A1764346412
Fallen DNA testing firm 23andMe won court approval of a bankruptcy plan that includes settlements to provide up to $62 million to resolve thousands of data breach claims.
Judge Brian C. Walsh of the US Bankruptcy Court for the Eastern District of Missouri approved the plan in a Wednesday order, overruling most creditor objections and challenges from data breach victims.
Many of those former customers’ objections were deemed moot or premature, and several of them didn’t appear at a court hearing on the plan.
Objections from the Justice Department’s bankruptcy watchdog and a coalition of state attorneys general were resolved ...
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
743
SEPTEMBER 2025
743
JULY 2020
726
Breach
24 Jul 2020 • Amtrak
National Railroad Corporation (Amtrak)
Amtrak Data Breach
653
MEDIUM-73
AMT653080525
The Maine Office of the Attorney General reported a data breach involving the National Railroad Corporation (Amtrak) on November 4, 2020. The breach, which occurred on July 24, 2020, involved an external system breach (hacking) affecting a total of 49,289 individuals, of which 214 were Maine residents. Amtrak offered 12 months of identity theft protection services through Experian to affected individuals.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2020
780
Breach
16 Apr 2020 • Amtrak
Amtrak
Amtrak Data Breach
722
LOW-58
AMT329072625
The California Office of the Attorney General reported a data breach involving Amtrak on May 28, 2020. The breach occurred on April 16, 2020, and unauthorized access was gained to Amtrak Guest Rewards accounts, potentially exposing usernames and passwords, but not financial data, credit card information, or Social Security numbers. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Amtrak ??
What was Amtrak's A.I Rankiteo Cyber Score in July 2026 ??
What was Amtrak's A.I Rankiteo Cyber Score in June 2026 ??
What was Amtrak's A.I Rankiteo Cyber Score in May 2026 ??
What was Amtrak's A.I Rankiteo Cyber Score in April 2026 ??
What was Amtrak's A.I Rankiteo Cyber Score in March 2026 ??
What was Amtrak's A.I Rankiteo Cyber Score in February 2026 ??
What was Amtrak's A.I Rankiteo Cyber Score in January 2026 ??
What was Amtrak's A.I Rankiteo Cyber Score in December 2025 ??
What was Amtrak's A.I Rankiteo Cyber Score in November 2025 ??
What was Amtrak's A.I Rankiteo Cyber Score in October 2025 ??
What was Amtrak's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Amtrak's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Amtrak ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Amtrak's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?