Where did ScotRail go so wrong with their app launch?
ScotRail's hurry to switch customers over to their new app left some major oversight.
30/07/2026
Rolling out a nationwide migration and a public launch on the same day was always going to end here, in chaos.
What actually went wrong?
Login and account issues
Migrating your entire user base without stress testing the login flow first is a bold choice, to say the least.
ScotRail told everyone to reset their password to regain access, so naturally, everyone tried to reset their password at the same time. Some service degradation here would've been forgivable, expected even. But when reset emails stop arriving entirely, or turn up two hours later, that's not degradation, that's a system that never saw this coming. Try explaining "the email's on its way" to someone who's got four minutes to make their train.
Ticket purchasing failures
Assuming you actually got in, the next job was buying a ticket, and this is where it properly fell apart. Users couldn't link railcards to their accounts. There was nowhere obvious to add card details. Entire stations were missing from the station list, on a train app. Not an edge case, not a weird regional halt nobody's heard of, just stations, gone. This is the one job the app has to do, and it couldn't reliably do it for a lot of people on day one.
Old (fallback) app broken
Here's the bit that turns "rough launch" into "no safety net whatsoever." The old app wasn't quietly retired in the background, it started actively working against people. Alerts nagging users to switch to the new app, popping up over the QR code they actually needed to board the train. Season ticket holders standing at a barrier, staring at a "download the new app" prompt instead of their ticket.
A broken new app with a working fallback is a bad launch day. A broken new app with a fallback that's been sabotaged into uselessness is a migration with no rollback plan, on the one day it needed one.
Lessons Learned
-
It's 2026, if you haven't heard of edge computing, I think it's time for your mid-day nap. ScotRail makes it obvious they're already using Cloudflare with the bombardment of bot checks I get every time I go to download an expense receipt. So why wouldn't they use Cloudflare's edge? Would of prevented a lot of the issues from launch.
-
Stress testing is vital to the development of any application and its infrastructure. ScotRail should have tested both thoroughly against the expected peak user throughput + more.
-
Canary releases exist for exactly this reason. Roll the new app out to 5% of users, watch it, then 20%, then 50%. Instead ScotRail went full big-bang, entire country, day one, no gradual rollout to catch this before it became a headline.
-
Feature flags would've let them kill the "old app now blocks your QR code" behaviour the second it started happening, instead of leaving people stranded at a barrier while engineers scrambled.
-
Where was the rollback plan? When a migration goes this sideways, the fallback isn't "tell everyone to use the old app" while that old app is actively fighting them too. A proper rollback means the previous version stays fully functional, untouched, until the new one's proven stable.
-
Observability. Someone, somewhere, should've had a dashboard lighting up red the second password reset emails started queuing for two hours. If that alert existed, nobody acted on it fast enough, and if it didn't exist, that's its own problem.
-
Communication was reactive, not proactive. Passengers found out their tickets weren't going to carry over from a warning buried in the news, not a push notification from the app itself, on the day it actually mattered.
