# Cyberattack on Spanish railway entities Renfe and Adif

> Live situation record from CLSTR: https://clstr.news/situations/cyberattack-on-spanish-railway-entities-renfe-and-adif
> Updated: 2026-09-27T20:56:44.000Z. Sources: 41. Developments: 2.

Spanish railway entities Renfe and Adif were targeted by a sophisticated cyberattack, potentially utilizing artificial intelligence to exploit system vulnerabilities. The breach originated in Adif’s digital infrastructure before spreading to Renfe’s cloud systems and various suppliers.

Initial reports indicated that approximately 500 gigabytes of data were stolen, which companies described as ‘limited’ information consisting primarily of customer names and email addresses. At that stage, officials ruled out the theft of banking details, financial data, or national ID numbers, and confirmed that railway operations remained fully functional.

Subsequent forensic analysis revealed a significantly larger impact, with approximately 150 million data records compromised. The stolen information is categorized into three distinct tiers:

• 20 million low-risk records containing names and national ID numbers (DNI).
• 20 million high-risk records including full names, dates of birth, phone numbers, and postal addresses.
• 100 million nominative ticket records, which could allow attackers to potentially map the travel patterns of specific individuals.

The attack was neutralized following intervention by Spain’s National Cryptologic Center (CCN). While the breach represents a significant escalation in threats to Spanish critical infrastructure, authorities have stated there is no evidence that sensitive banking or payment information was accessed.

## Claims

- The stolen data includes 20 million low-risk records (names and IDs), 20 million high-risk records (full personal details), and 100 million nominative ticket records. (disputed by 5 sources)
- The cyberattack primarily accessed limited user information such as names and email addresses. (disputed)
- Forensic analysis indicates that approximately 500 GB of data containing over 150 million records were stolen. (corroborated by 6 sources)
- There is currently no evidence that banking, financial, or credit card information was accessed. (corroborated by 4 sources)
- The cyberattack is reported to have been executed using artificial intelligence. (corroborated by 3 sources)
- Railway operations and train services were not affected by the cyberattack. (corroborated by 3 sources)
- The incident has been reported to Spain's National Cryptologic Center (CCN). (corroborated by 3 sources)
- The company detected several weeks of attempted attacks prior to the successful breach. (single source)

## Timeline

### 2026-09-27: Adif and Renfe cyberattack compromises 150 million user records

A cyberattack on Spain's Adif and Renfe has compromised 500 GB of data, including 150 million records. The breach, potentially involving AI, exposed personal details and travel histories of millions.

11 sources. https://clstr.news/cluster/adif-and-renfe-cyberattack-results-in-theft-of-150-million-data-records

### 2026-09-25: Renfe and Adif hit by AI-driven cyberattack compromising customer data

Spanish railway operators Renfe and Adif suffered a cyberattack, allegedly using AI, compromising approximately 500GB of limited user data, including names and emails, while train services remain operational.

34 sources. https://clstr.news/cluster/renfe-and-adif-suffer-cyberattack-exposing-user-data

---
Cite as: Cyberattack on Spanish railway entities Renfe and Adif. CLSTR, https://clstr.news/situations/cyberattack-on-spanish-railway-entities-renfe-and-adif
