Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 40 sources · 3 days · First seen · Last updated
Cyberattack on Spanish railway entities Renfe and Adif
Overview
Spanish railway entities Renfe and Adif were targeted by a sophisticated cyberattack, potentially utilizing artificial intelligence to exploit system vulnerabilities. The breach originated in Adif’s digital infrastructure before spreading to Renfe’s cloud systems and various suppliers.
Initial reports indicated that approximately 500 gigabytes of data were stolen, which companies described as ‘limited’ information consisting primarily of customer names and email addresses. At that stage, officials ruled out the theft of banking details, financial data, or national ID numbers, and confirmed that railway operations remained fully functional.
Subsequent forensic analysis revealed a significantly larger impact, with approximately 150 million data records compromised. The stolen information is categorized into three distinct tiers:
• 20 million low-risk records containing names and national ID numbers (DNI). • 20 million high-risk records including full names, dates of birth, phone numbers, and postal addresses. • 100 million nominative ticket records, which could allow attackers to potentially map the travel patterns of specific individuals.
The attack was neutralized following intervention by Spain’s National Cryptologic Center (CCN). While the breach represents a significant escalation in threats to Spanish critical infrastructure, authorities have stated there is no evidence that sensitive banking or payment information was accessed.
Entities
Spain · Renfe · Adif · Ministry of Transport · Anthropic
Claims
What the coverage asserts, and how many sources carry each claim.
Coverage disagrees
Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.
-
"The cyberattack primarily accessed limited user information such as names and email addresses." thecyberexpress.com
vs
"The stolen data includes 20 million low-risk records (names and IDs), 20 million high-risk records (full personal details), and 100 million nominative ticket records." www.elmundo.es · www.merca2.es · www.ocu.org · www.preferente.com · www.xataka.com
The first claim specifies a breakdown of 140 million high/low-risk and ticket records, while the second claims the attack primarily accessed only limited information like names and emails.
- [DISPUTED] The stolen data includes 20 million low-risk records (names and IDs), 20 million high-risk records (full personal details), and 100 million nominative ticket records. www.elmundo.es · www.merca2.es · www.ocu.org · www.preferente.com · www.xataka.com
- [DISPUTED] The cyberattack primarily accessed limited user information such as names and email addresses. thecyberexpress.com
- [● 6 SOURCES] Forensic analysis indicates that approximately 500 GB of data containing over 150 million records were stolen. www.elmundo.es · www.moncloa.com · www.merca2.es · www.ocu.org · www.preferente.com · +1 more
- [● 4 SOURCES] There is currently no evidence that banking, financial, or credit card information was accessed. www.elmundo.es · thecyberexpress.com · www.preferente.com · www.que.es
- [● 3 SOURCES] The cyberattack is reported to have been executed using artificial intelligence. www.elmundo.es · www.moncloa.com · wwwhatsnew.com
- [● 3 SOURCES] Railway operations and train services were not affected by the cyberattack. www.que.es · thecyberexpress.com · wwwhatsnew.com
- [● 3 SOURCES] The incident has been reported to Spain's National Cryptologic Center (CCN). www.elmundo.es · www.que.es · wwwhatsnew.com
- [○ 1 SOURCE] The company detected several weeks of attempted attacks prior to the successful breach. thecyberexpress.com
Timeline
-
1 day ago
[TECHNOLOGY] 10 sourcesAdif and Renfe cyberattack compromises 150 million user recordsA cyberattack on Spain's Adif and Renfe has compromised 500 GB of data, including 150 million records. The breach, potentially involving AI, exposed personal details and travel histories of millions.
-
4 days ago
[TECHNOLOGY] 34 sourcesRenfe and Adif hit by AI-driven cyberattack compromising customer dataSpanish railway operators Renfe and Adif suffered a cyberattack, allegedly using AI, compromising approximately 500GB of limited user data, including names and emails, while train services remain operational.
Sources
324.cat · ara.cat · atlantico.net · beteve.cat · cantabriaeconomica.com · capital.es · centre-cerlatez.ch · cronicadecantabria.com · deia.eus · diariodetransporte.com · economiadigital.es · elburgado.com · elcorreoweb.es · eldiario.es · ep01.epimg.net · information.tv5monde.com · jurnaluldearges.ro · kyivpost.com · la-croix.com · lacronicabadajoz.com · laopinioncoruna.es · laregion.es · lavanguardia.com · levante-emv.com · libertaddigital.com · merca2.es · moncloa.com · noticiasdemalaga.es · noticiasdeNavarra.com · ocio.farodevigo.es · ocu.org · preferente.com · que.es · thecyberexpress.com · theobjective.com · thesun.my · todoalicante.es · upday.com · wwwhatsnew.com · xataka.com
This summary has been updated 1 time: see revision history