Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Monday 22 December 2025 7:12 am  |  Updated:  Monday 22 December 2025 7:18 am

Eurostar’s new AI chatbot left customers exposed

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
Eurostar recently revealed plans to launch a direct service between London, Germany and Switzerland for the first time.
The vulnerabilities were first reported to Eurostar on 11 June 2025

Eurostar’s shiny new AI chatbot was billed as a smarter way of helping customers. But the bot was shipped with old-fashioned security flaws that could have left customers exposed, and for weeks, nobody at the train operator seemed willing to listen.

City PM can reveal that multiple security flaws were found in Eurostar’s public-facing AI chatbot, all while the company was rushing to embed AI into a consumer product.

The chatbot, a customer tool sitting atop of a large language model (LLM), was originally designed to handle general enquiries, rather than access any sensitive system.

The European rail operator has claimed that it was never connected to customer accounts or internal platforms, and that no data was put at risk, as all customer information remains protected behind login barriers.

Nonetheless, the flaws, which have now since been fixed, underline how easily ‘AI powered’ front ends could create a false sense of security.

Security researchers at Pen Test Partners raised concerns under Eurostar’s published ‘vulnerability disclosure policy’, flagging a series of weaknesses that showed how the chatbot’s controls could be bypassed in practoce.

Those reports were submitted responsibly and within scope, City PM understands.

Eurostar: Solid-looking guardrails

The most alarming issues in the Eurostar system was a guardrail bypass.

While the chatbot appeared to enforce strict content controls, only the most recent message in a conversation was properly validated server side.

Meanwhile, all the other, prior messages, could be altered client-side and quietly fed back into the model as ‘trusted’ context.

In practice, that meant an attacker could send a harmless final message to pass checks – while actually smuggling a malicious or manipulative prompt earlier in the chat history.

Once past the guardrails, the chatbot could be steered into revealing internal details like its system prompt and underlying information.

The latter risks an awkward exposure for any company, and a potentially dangerous one if the bot were later connected to personal data or account details.

Other weaknesses included conversation and message IDs that weren’t properly verified, and an HTML injection flaw that allowed JavaScript to run inside the chat window.

This was initially a harmless input, but with a plausible path to something more serious should chats ever be replayed or shared.

Read more

AllianzGI chief executive warns of  AI ‘socialism’ as investors lean on chatbots

Allianz is set to cut 650 jobs in the UK.

“No attempt was made to access other users’ conversations or personal data”, PTP said.

“But the same design weaknesses could become far more serious as chatbot functionality expands”.

Eurostar stressed that customer data was in this case not at risk.

A spokesperson told City PM: “The chatbot did not have access to other systems and more importantly no sensitive customer data was at risk. All data is protected by a customer login.”

Disclosure derailment

If the tech issues were concerning, the disclosure process raised even more eyebrows.

The vulnerabilities were first reported to Eurostar on 11 June 2025 via the company’s vulnerability disclosure email address.

There was no acknowledgement, and a follow-up on 18 June also went unanswered.

After nearly a month of silence, the issue was escalated privately via Linkedin to Eurostar’s head of security, who said to use the rail giant’s ‘vulnerability disclosure programme’, which had already been done.

Weeks later, Eurostar had either changed or outsourced its disclosure process mid-way through, meaning there was no longer any record of the disclosure.

During the back and forth, Eurostar even issued blackmail accusations for persisting in trying to get the issues addressed.

Eurostar said it encourages responsible disclosure and reviews of all reports carefully, claiming that “any issues identified during early testing were addressed promptly, and we continue to monitor and strengthen our security controls”.

The flaws were eventually fixed.

Old problems with a new wrapper

Eurostar’s chatbot relied on familiar web and API plumbing like message histories, IDs, and signatures.

The transport giant said the chatbot was an experimental service, and that it has a “well-established cyber security governance framework, including the use of external ethical hacking specialists”.

Read more

Space X to allow British investors to buy into blockbuster IPO  

Elon Musk's SpaceX IPO

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • AI
  • artificial intelligence
  • chatbot
  • customer service
  • Eurostar
  • guardrails
  • llm
  • LLMs
  • security
  • Transport

Trending Articles

  • Revealed: Secret Treasury plan to tax State Pension before it is paid out

  • Two solicitors linked to Post Office scandal charged with misconduct

  • Burnham’s new chief of staff ran City firm advising Thames Water and rival Heathrow bidder

  • Barclays and Lloyds join banking sector plan for digital ID

  • Clarkson’s Farm and why businesses must stop blaming the weather

More from City PM

  • AllianzGI chief executive warns of  AI ‘socialism’ as investors lean on chatbots

    Investing
    Allianz is set to cut 650 jobs in the UK.
  • Space X to allow British investors to buy into blockbuster IPO  

    Investing
    Elon Musk's SpaceX IPO
  • SpaceX snaps up AI coding darling Cursor as valuation soars past Amazon

    Tech
    Elon Musk speaking at a tech conference, wearing a suit, with a futuristic backdrop highlighting space exploration themes
  • Millions left unclaimed as public awareness gap exposes flaws in class actions

    Legal
    SWR was previously owned by FirstGroup and MTR Corporation, but is now the responsibility of DfT (Department for Transport) Operator. (A South Western train arrives at Clapham Junction. Photo by Jack Taylor/Getty Images)
  • VodafoneThree enters race for TalkTalk customers with takeover bid

    Telecoms
    Vodafone CEO Margherita Della Valle discussing UK expansion strategy after £4.3bn Vodafone-Three telecoms deal at press c...
  • ‘Safe’ version of Anthropic’s Mythos model hits market

    Tech
    Anthropics AI technology showcased at a tech conference, highlighting innovative advancements in artificial intelligence
  • Andrew Bailey warns on AI: ‘Everybody is currently priced to be a winner’

    Tech
    Bank of England Governor Andrew Bailey said cited several indicators that the labour market was softening.
  • Survey: Nearly All European Organisations Feel Pressure to Scale AI for Customer Experience, Yet Only 38% Have a Clear Approach to Governance

    Business Wire

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy