< Back to all clusters
[TECHNOLOGY] · Spain · 30 sources

started · updated

Renfe and Adif hit by AI-driven cyberattack compromising user data

Spanish rail operator Renfe and infrastructure manager Adif have confirmed they were victims of a cyberattack that compromised user data. The breach originated in Adif's servers, which were previously compromised and interconnected with Renfe's systems.

Preliminary investigations indicate that attackers accessed approximately 500 gigabytes of data. The compromised information is described as “limited,” consisting primarily of customer names and email addresses. Renfe stated there is no evidence that this data has been publicly released, nor is there evidence of access to sensitive information such as banking details, payment methods, or national ID numbers.

Reports suggest the attack was highly sophisticated, potentially utilizing artificial intelligence—specifically a system similar to Anthropic’s AI—to identify system vulnerabilities. This marks a notable instance of AI-driven cyberattacks targeting a Spanish public entity.

Adif detected unusual activity late on a Thursday. In response, both companies activated security protocols, isolated affected environments, and engaged independent cybersecurity specialists. While Adif's website was rendered unavailable for several days, both organizations emphasized that rail traffic and services remain fully operational and unaffected.

Entities

Adif · Anthropic · National Cryptologic Centre · Renfe · Spain

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

about 3 hours ago
about 11 hours ago