started · updated
Adif and Renfe cyberattack compromises 150 million user records
A major cyberattack targeting Spain’s state-owned railway infrastructure manager, Adif, and operator, Renfe, has resulted in the theft of approximately 500 GB of data. While initial reports suggested the breach was limited to names and email addresses, subsequent forensic analysis reveals that over 150 million data records were compromised.
The stolen information is categorized into three tiers: 20 million low-risk records containing names and IDs; 20 million high-risk records including full names, dates of birth, phone numbers, and postal addresses; and 100 million nominative ticket records. The latter allows attackers to potentially map the travel patterns of specific individuals.
Reports indicate the attack may have been executed using artificial intelligence, marking a significant escalation in cyber threats to Spanish critical infrastructure. Although the breach originated on Adif servers, train services and operational systems remained unaffected. Authorities, including the National Cryptologic Center, are investigating. Currently, there is no evidence that sensitive banking or payment information was accessed.
Entities
Adif · Centro Criptológico Nacional · Ministry of Transport · National Cryptologic Center · Renfe · Spain
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The company detected several weeks of attempted attacks prior to the successful breach. thecyberexpress.com
- [DISPUTED] The cyberattack primarily accessed limited user information such as names and email addresses. thecyberexpress.com
- [● 3 SOURCES] The cyberattack is reported to have been executed using artificial intelligence. www.elmundo.es · www.moncloa.com · wwwhatsnew.com
- [● 3 SOURCES] Railway operations and train services were not affected by the cyberattack. thecyberexpress.com · wwwhatsnew.com
- [DISPUTED] The stolen data includes 20 million low-risk records (names and IDs), 20 million high-risk records (full personal details), and 100 million nominative ticket records. www.elmundo.es · www.merca2.es · www.ocu.org · www.preferente.com · www.xataka.com
- [● 6 SOURCES] Forensic analysis indicates that approximately 500 GB of data containing over 150 million records were stolen. www.elmundo.es · www.moncloa.com · www.merca2.es · www.ocu.org · www.preferente.com · +1 more
- [● 3 SOURCES] The incident has been reported to Spain's National Cryptologic Center (CCN). www.elmundo.es · wwwhatsnew.com
- [● 4 SOURCES] There is currently no evidence that banking, financial, or credit card information was accessed. www.elmundo.es · thecyberexpress.com · www.preferente.com