Phony texts, emails promising Amtrak Guest Rewards cards at steep discounts or fictitious refunds: scammers are getting more inventive to steal travelers’ banking data. Here’s how to spot these traps and protect yourself.
An Amtrak email urging you to act? Better to be wary!
The summer travel season is a prime time for cybercriminals. As millions of Americans book train tickets or check itineraries, scammers seize the heightened activity to spread fake messages imitating Amtrak, among others. For weeks, the rail company has been issuing warnings about a surge in phishing campaigns—phishing that spreads via SMS, email, or messaging apps.
The scam is simple in principle: scammers push victims to click on a fraudulent link to harvest their financial details, login credentials, or other personal information. The offers shown often appear credible, because they faithfully reproduce Amtrak’s branding and leverage especially attractive promotions. To convince victims to act quickly, cybercriminals also play on scarcity and urgency. Some campaigns promise Amtrak Guest Rewards cards with exceptional discounts that can reach up to 95%, while others tout the distribution (fictitious, of course) of 300,000 cards available for only 48 hours. These eye-catching figures are designed to short-circuit reflection and push users to click immediately.
Other messages talk about a pending ticket refund, exceptional compensation, a $500 gift card, or a reward tied to a loyalty program. The mechanism remains the same: once the link is opened, the user is redirected to a fake site that reproduces Amtrak’s Connect appearance in order to ask for personal or financial details. This tactic works especially well because scammers regularly tailor their scripts to the rail company’s current promotions and news. Promotional periods, holiday travel, or announcements about loyalty programs become pretexts for new, highly convincing scam campaigns.
How to recognize a scam using Amtrak’s name?
Even when a message looks authentic, several clues can reveal a fraud attempt. The first reflex is to carefully check the sender’s address. Amtrak reminds that its official communications come from clearly identified domains, notably those ending in @amtrak.com, @info.amtrak.com, @newsletter.amtrak.com, or @connect.amtrak. An unusual address, or one with typos or extra characters, should raise immediate suspicion.
The message’s content also warrants close attention. Scams almost always hinge on an exceptionally advantageous offer or a threat of losing a perk if no action is taken quickly. A spectacular discount, an unexpected refund, or a very generous reward should prompt caution, even if the message seems to originate from Amtrak.
Another warning sign: the presence of a link inviting you to enter personal or banking information. Amtrak reminds customers that it never asks for payment details, passwords, or other confidential information via SMS, email, or through social media. Any such request is a strong indicator of a scam. Cybercriminals aren’t limited to email anymore. Fake accounts circulate on Messenger or WhatsApp to approach travelers directly. Again, scammers use the company’s logo and reassuring language to establish trust before sending a fraudulent link or requesting sensitive information.
Finally, the safest, simplest path is often best: instead of clicking a link in a message, open your browser and log in directly to Amtrak.com or use the official Amtrak app. This precaution stops the vast majority of phishing attempts, even when they’re highly sophisticated.