Blog
Cyber Threat Intelligence

Rail Fraud: Fare Evasion, Delay Repay Abuse & Telegram Scams

Fraud against rail operators extends well beyond fare dodging. CYJAX breaks down how compensation scheme abuse, insider fraud and Telegram marketplaces for discounted tickets are combining to create a persistent revenue threat across the UK rail sector.

August 28, 2026
8
min read
Shail Yadav
Marketing Executive
Table of contents
Share

Key takeaways

  • Fare evasion spans simple, low-effort tactics through to coordinated digital fraud, and both are hard to police at scale
  • Delay Repay abuse using false identities has generated six-figure illicit gains from a single operation
  • Staff discount schemes and large infrastructure contracts create insider and corporate fraud exposure alongside customer-facing risks
  • CYJAX has observed an active Telegram marketplace selling discounted rail travel fraud, using forwarded customer feedback to build trust with buyers

Rail fraud is often reduced to fare dodging in the public imagination, but the reality facing operators is considerably broader. From compensation scheme abuse to insider misuse of staff discounts, and an active Telegram marketplace selling discounted travel, the rail sector is contending with a fraud landscape that is organised, persistent, and difficult to mitigate at scale.

Fare evasion remains a constant drain

Fare evasion techniques range from the low effort to the highly deliberate. Passengers are known to buy tickets for shorter journeys than they travel, tailgate through barriers, select stations without ticket checks, or use discounted tickets they do not qualify for. Doughnutting, where an individual boards and travels without a ticket at all, remains one of the simplest and most common methods. Revenue protection officers are the primary line of defence, but both unsophisticated evasion and more calculated digital fraud are hard to catch consistently across a national network.

Delay Repay schemes are being systematically abused

Compensation schemes designed to reassure passengers are themselves a fraud vector. The UK's Delay Repay scheme has been exploited using false identities and offshore or virtual financial accounts to purchase tickets purely to claim compensation on late services, without the fraudster ever travelling. One operation running between October 2021 and February 2025 involved over 447 fraudulent transactions and generated £140,000 in illicit funds, with two Leeds-based students eventually jailed after CrossCountry Trains flagged the pattern to British Transport Police. Digital ticketing, which is automatically tracked at the point of use, makes this harder to run, but the risk from physical tickets persists.

Insider threat and corporate fraud add another layer

Employee-facing schemes carry their own exposure. Rail Staff Leisure Cards, which give UK rail employees and registered family members a 75% discount on leisure travel, can be abused by staff registering individuals unrelated to them so the discount is claimed under an apparent legitimate use case. At the corporate level, large infrastructure contracts are vulnerable to inflated invoicing and payroll misrepresentation, illustrated by issues uncovered during the HS2 programme, where self-employed workers were falsely declared as salaried staff on inflated payslips by a subcontractor supplying labour to the West Midlands section of the route.

A Telegram marketplace is selling the fraud itself

Perhaps the most striking element is how visible this activity has become. CYJAX has identified threat actors on Telegram actively advertising and requesting fraud services targeting major UK rail brands. Discounts observed on offer ranged from 50% to 65%, frequently with no minimum ticket value, and some sellers cap the maximum ticket price without disclosing whether this reflects the underlying fraud method. To build credibility, sellers forward screenshots of satisfied customers and successful bookings, a tactic designed to reassure prospective buyers and drive repeat custom.

Read the full report

This is one strand of a much wider threat picture facing the rail sector. CYJAX's report, CYJAX Gets Rail, covers the cyber, physical, and supply chain threats affecting rail operators globally, including social engineering, OT protocol vulnerabilities, ransomware and data extortion, and activism-driven disruption. Read the full report to understand the complete threat landscape.

Subscribe for weekly updates

Receive our latest cyber intelligence insights delivered directly to your inbox

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share
Get started

Get Started with CYJAX CTI

Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.

Link Copied