Independent Reviews
Abstract glass data vault fractured by a security breach
Data Breach Published 1 Sept 2026Updated 2 Sept 2026 4 min read1 source

P&O Ferries Says Passenger Data Link Was Shared on One Sailing

P&O Ferries says a link containing certain personal information about customers on one Calais-to-Dover sailing was inadvertently shared with several other passengers. The ICO has received the incident report and is assessing it.

By VPN Rocks Editorial Team

The short version

What you need to know

  • P&O Ferries says a link containing certain personal information relating to customers on a single Calais-to-Dover sailing was inadvertently shared with a number of other customers on 31 August.
  • The operator has not publicly specified the fields involved or how many people received the link. It says it is contacting affected customers directly; the ICO says it is assessing the incident report.
  • Read the direct notice, ask P&O which data and access window applied to you, and be alert for travel-themed impersonation. A VPN cannot revoke a link or recover information already exposed.

What has P&O Ferries confirmed?

P&O Ferries told the BBC that an isolated incident occurred on the morning of 31 August on one Calais-to-Dover sailing. It says a link containing certain personal information relating to customers on that vessel was inadvertently shared with a number of other customers.

The operator says it is contacting impacted customers and will keep them informed. The Information Commissioner's Office confirmed that P&O reported an incident and said it is assessing the information provided.

What is not yet public

The BBC report does not identify the categories of personal information in the link, the number of affected passengers, how many recipients received it, how long it remained accessible or whether anybody opened or retained it. Those gaps matter when judging individual risk.

Do not turn an inadvertently shared link into an unsupported claim of hacking, identity theft or wider compromise of P&O systems. Affected customers should rely on the operator's direct notice for incident-specific details and updates.

What affected passengers can do now

Check that any incident message came through a known P&O channel, then ask which fields related to you, who could access the link, when access was disabled and whether the operator recommends any account action. Keep the notice and avoid replying with more personal information than is needed.

Be cautious of messages that mention a real crossing, refund or travel disruption and then request payment, a password or identity document. Open the operator's official site independently or use a number from an existing booking confirmation rather than a contact route supplied in an unexpected message.

Where a VPN helps — and where it does not

A reputable VPN can encrypt a supported device's connection over public Wi-Fi on a ferry or at a terminal, reducing exposure to the local network while you use legitimate online services.

This incident concerns a data link shared with other customers. A VPN cannot withdraw that link, control a recipient's copy, determine which records were accessed or reverse any disclosure. Link access controls, prompt revocation, clear notification and careful follow-up verification are the relevant measures.

VPN Rocks view

A narrowly scoped incident still needs precise communication. Passengers need to know the affected data fields and access window before they can judge whether the likely consequence is inconvenience, targeted phishing or something more serious.

Travel providers should use expiring, recipient-bound links for sensitive records and test that one passenger cannot open another customer's information. Notices should also tell customers exactly which communication channels the company will use next.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps