> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked
- URL: https://darkwebinformer.com/viking-line-ferries-allegedly-breached-with-full-passenger-database-and-payment-data-leaked/
- Published: 2026-03-11T16:07:11.000Z
- Updated: 2026-03-11T16:07:11.000Z
- Author: Dark Web Informer
- Tags: Leaks

Dark Web Informer - Cyber Threat Intelligence 

# Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked

March 11, 2026 - 2:46:18 PM UTC 

![Finland](https://flagcdn.com/20x15/fi.png)Finland 

Transportation / Maritime 

Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. 

[ View API](https://darkwebinformer.com/api-details/) 

 Unlock Exclusive Cyber Threat Intelligence

Powered by DarkWebInformer.com

Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

## Quick Facts

Date & Time 2026-03-11 14:46:18 UTC 

Threat Actor bytetobreach 

Victim Country ![Finland](https://flagcdn.com/20x15/fi.png)Finland 

Industry Transportation / Maritime 

Victim Organization Viking Line 

Victim Site vikingline.com 

Category Data Breach 

Severity Critical 

Network Open Web 

Total Records Unknown 

##  Incident Overview

A threat actor going by bytetobreach claims to have breached Viking Line, a major Finnish ferry transportation company operating in the Baltic Sea. The actor says they have extracted a complete database of traveler personal information, including vehicle registration plates, and has made the data available for free download with multiple backup links.

  
A second complementary database was also compiled through the NetAxept payment API, which is used by companies for processing payments at onboard restaurants and services during ferry journeys. The actor says this database correlates passenger identities with transaction data from all Viking Line ships. The actor notes that a routine check on the passenger data shows above-average wealth profiles, mentioning a Finnish filmmaker found among the first entries as an example.

  
The threat actor also detailed the attack chain used to gain access: exploiting a Solr LFI vulnerability dating back to 2021 to grab Tomcat credentials, uploading a reverse shell via JSP, then using the same Tomcat credentials to pivot to the master server, followed by abuse of the NetAxept payment integration. The listing includes redacted database links, LFI paths, initial foothold details, frontend/backend access, and system accounts.

##  Compromised Data Categories

 Traveler Personal Information  Vehicle Registration Plates  Onboard Payment Transaction Data  Restaurant & Service Purchase History  Passenger-to-Ship Correlation Data  System Accounts & Credentials  Frontend/Backend Access 

### Claim URL - For Subscribers Only

The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

##  Image Preview

[![Forum listing showing Viking Line Ferries breach with passenger database and payment data](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/88495604302619851312.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/88495604302619851312.png) 

Dark Web Informer © 2026 | Cyber Threat Intelligence  
[DarkWebInformer.com](https://darkwebinformer.com/)