Data Breaches

Amtrak Says Guest Rewards Accounts Hacked in Credential Stuffing Attacks

National passenger railroad company Amtrak is notifying customers that hackers have breached their Guest Rewards Accounts.

National passenger railroad company Amtrak is notifying customers that hackers have breached their Guest Rewards Accounts.

Amtrak is notifying some customers that their Guest Rewards Accounts have been hacked.

According to a notification letter to the affected individuals, a copy of which was submitted to the state of Massachusetts, no Amtrak systems were compromised in the attacks, as credential stuffing was employed.

As part of such attacks, threat actors leverage username and password combinations obtained from other data breaches, from malware infections, or phishing, in an attempt to gain access to accounts that use the same login credentials.

“We believe that the unauthorized party may have obtained your login credentials from third-party sources. We have no indication that your login credentials were obtained from our systems,” Amtrack says.

The national passenger railroad company says that the attackers started accessing the targeted accounts on May 15, 2024, and that they were evicted on May 18, after the credentials for the compromised accounts were reset.

The attackers, Amtrack says, were seen changing the email addresses for the hacked accounts and accessing profile information, including names, contact details, dates of birth, Amtrak Guest Rewards account numbers, partial credit card numbers and expiration dates, gift card information, and details about transactions and trips.

Advertisement. Scroll to continue reading.

“Promptly after becoming aware of the issue on May 15, 2024, we began an investigation and took steps to secure your account. We have changed the email address for your Amtrak Guest Rewards account back to your email address and initiated a reset of your account password,” the company says.

Amtrak urges the affected individuals to reset their account passwords and to change the credentials for other online accounts secured with the same or similar usernames and passwords, and to use multi-factor authentication for their Amtrak Guest Rewards accounts.

The impacted individuals are also advised to order free credit reports, to review account statements to discover fraud and identity theft and report such incidents, and to consider placing a fraud alert on their credit files.

What Amtrak did not say was how many individuals might have been affected by the incident. SecurityWeek has emailed the company for additional details and will update this article as soon as a reply arrives.

Related: Okta Warns of Credential Stuffing Attacks Targeting Cross-Origin Authentication

Related: 340,000 Jason’s Deli Customers Potentially Impacted by Credential Stuffing Attack

Related: Over 71k Impacted by Credential Stuffing Attacks on Chick-fil-A Accounts

Related: PayPal Warns Users of Credential Stuffing Attacks

Related Content

Data Breaches

Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.

Data Breaches

Nathan Austad admitted in court to launching a credential stuffing attack against a fantasy sports and betting website.

Data Breaches

Hackers accessed user accounts and compromised names, addresses, phone numbers, email addresses, and other information.

Data Breaches

Threat actors steal personal information from thenorthface.com user accounts in a recent credential stuffing campaign.

Black Hat

SaaS app log analysis highlights the rapid smash and grab raid: in, steal, and leave in 30 minutes.

Malware & Threats

Okta raises the alarm on credential stuffing attacks targeting endpoints used for cross-origin authentication.

Identity & Access

Okta warned of a spike in credential stuffing attacks using anonymizing services.

Cybercrime

Joseph Garrison has received an 18-month prison sentence for accessing 60,000 DraftKings user accounts using credential stuffing.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version