Deutsche Bahn reported a cyberattack that disrupted its passenger information and ticketing services, temporarily impacting travelers’ ability to access timetable information and book tickets. The outage affected both the DB Navigator mobile app and the bahn.de website, with service instability occurring in multiple waves before systems were brought back to a largely stable state with some temporary limitations.
Deutsche Bahn said its defensive measures helped limit customer impact and that it was coordinating with federal authorities, but it did not attribute the attack or provide details on any perpetrator contact. Reporting identified the incident as a distributed denial-of-service (DDoS) attack that knocked the booking and timetable systems offline for hours; the company also did not confirm whether any customer data was compromised.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
By around 13:00 UTC on 2026-02-18, Deutsche Bahn had restored its website and key booking and timetable systems, though some temporary limitations remained. The company later said systems had been largely stable since the evening and that operations had fully recovered.
After IT problems emerged on Tuesday afternoon and recurred on Wednesday morning, Deutsche Bahn said its experts were analyzing the cause and working to resolve the incident. The company stated that defensive countermeasures were in place to reduce the impact on customers and that it was in contact with federal authorities.
A large-scale distributed denial-of-service attack started on Deutsche Bahn's systems on 2026-02-17 at about 15:45 UTC, disrupting bahn.de and the DB Navigator app. The attack came in waves and affected booking, timetable, and passenger information services for several hours.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.