Travel data of nearly one million women exposed at public transport operator
Why collecting less data is the stronger defence
A data breach at a public transport operator exposed the travel information and personal data of nearly one million women — highlighting the systemic risks of collecting more data than necessary.

A public transit operator suffered a serious data breach, compromising sensitive passenger information belonging to nearly one million women. The breach occurred because the organisation collected far more personal data than operationally necessary — storing detailed travel records directly linked to individual identities, including movement patterns, route histories, and personal identification data.
This incident illustrates a pattern that repeats across sectors. Organisations maintain centralised databases containing far more personal information than any single transaction requires. When a vulnerability emerges anywhere in the system — or in any of its interconnected partner systems — all of that stored data is at risk simultaneously.
The root cause is architectural. Systems designed to share complete datasets by default create exposure that stronger security measures alone cannot eliminate. The solution is not more security on top of bad data practices — it is rethinking how personal information flows between organisations in the first place.
Verifiable credentials offer a different approach. Rather than exchanging full identity records, organisations verify only the specific claim required for a transaction. Individuals hold their information in personal wallets. Nothing unnecessary is ever shared — and what is never shared cannot be breached.
This approach aligns with privacy-by-design principles and is already practical to deploy. As regulatory requirements intensify and breach costs escalate, organisations that adopt credential-based verification are building infrastructure that is inherently more resilient.
Want to know more?
Curious about how this applies to your organisation, or want to talk to us about a specific use case? Get in touch — we're happy to help.