Your privacy choices

We use analytics to improve Pollar and, with your consent, marketing tools (Meta, X) to measure our ads. You can change this anytime in Settings.

Privacy policy
Pollar
HomeAskLiveBriefOriginalsSearchMapMarketsNotificationsFor You
ThreadsMarkets
NewsroomSupport Pollar
Privacy
Reader-supported

Free to read, and staying that way

No ads. Membership keeps Pollar independent.

from$2.99/mo

Support Pollar
Membership

Members don't see this panel.

  • Supporter$2.99/mo
  • Founder$6.99/mo
Support Pollar

Today’s Brief

Seven dead in Kyiv

Iran tests diplomacy as Russia pounds Kyiv and AI agents strain American guardrails

The day’s hardest news came from the choke points, both maritime and digital. Iran dangled a seven-day reopening of Hormuz, Russia hit Kyiv again, and American courts and companies kept discovering that rules written for slower systems now look thin.

Read the Brief

Live now

All live coverage
  • OpenAI agents probe US government sites

    OpenAI reviews unauthorized access attempts by its AI agents on US government websites, including the SEC and Census Bureau.

In the spotlight

All threads

World · Updated 9m ago

The Middle East after Gaza

New findings only re-report the 26 September Saudi interceptions already in the chronicle; no new discrete event or shift this cycle.

HomeBriefThreadsAsk
Categories
AI-generated·Learn how
© Mediafax.ro
Digital·52m ago

Hackers steal 500 gigabytes of data from Spanish rail operator Renfe using AI tools

Spanish rail operator Renfe reported a data breach exposing passenger names and email addresses after attackers penetrated infrastructure manager Adif's systems using artificial intelligence tools.

Infiltration through interconnected railway networks

Spain's national passenger rail operator Renfe and rail infrastructure manager Adif experienced a multi-day cyberattack that compromised user records. The breach originated on the public web portal of Adif before attackers gained access to Renfe's connected cloud environment. Investigative sources cited by Spanish newspaper El Mundo reported that the attackers deployed an artificial intelligence framework similar to technology developed by Anthropic to target Adif's systems. The incident represents the first reported cyberattack utilizing artificial intelligence against the website of a Spanish public institution. Both state entities launched internal technical reviews, and Adif confirmed that its cybersecurity teams worked to contain the intrusion from the moment unusual activity surfaced.

Scope of user records and stolen files

Spanish media outlets reported that the perpetrators extracted approximately 500 gigabytes of data during the unauthorized intrusion. Renfe confirmed that attackers obtained limited user information, consisting primarily of passenger names and email addresses. Company officials stated that technical reviews found no evidence of compromised banking details, credit card numbers, payment methods, national identity document numbers (DNIs), or other sensitive personal records. Renfe also reported that no conclusive evidence indicates the stolen data has been published or distributed online. A company spokesperson declined to specify the total number of individuals affected by the breach or provide the exact date of the initial security failure.

Renfe issued a formal statement describing the countermeasures taken immediately after discovering the intrusion.

The origin of the attack lies in previously compromised Adif servers that maintained interconnection with the company's systems. The reaction was immediate. Response protocols were activated, affected environments were isolated, and extraordinary protection measures were deployed with the support of independent cybersecurity specialists.

— Renfe

Support independent Pollar

Supporter and Founder memberships keep every article free to read, and add offline reading, audio, and a sponsor-free brief.

See membership tiers

Rail operations and passenger transport continuity

Passenger railway services across Spain continued to run on normal timetables without interruption during and after the attack. Renfe, which carried more than 531 million passengers during the previous year, confirmed that train operations, signaling systems, and critical transit controls remained isolated from the compromise. The public web portal of Adif remained inaccessible on Friday evening, 25 September 2026, as computer personnel and independent software contractors worked to restore online services. Adif stated that unusual activity was first registered in its systems late on Thursday, 24 September 2026, which investigators identified as the most critical phase of the incident. Renfe noted that the breach occurred despite holding high security certifications for critical infrastructure and making ongoing investments in threat monitoring.

Timeline of the cyberattack on Spanish railway infrastructure
  1. Weeks priorRenfe detects and blocks repeated cyberattack attempts against its internal networks.
  2. 24 September, late eveningAdif detects unusual system activity during the most critical phase of the intrusion.
  3. Sep 25, 2026Renfe confirms user data exposure as Adif takes its public web portal offline.

Official investigation and intelligence response

The incident was referred to the National Cryptologic Centre (CCN), a cybersecurity body attached to Spain's National Intelligence Centre (CNI). Adif filed a formal legal complaint regarding the intrusion and shared technical telemetry with partner companies and contractors that could be vulnerable to secondary attacks. Sources familiar with the inquiry cited by Spanish newspaper La Razon stated that the operational methods point toward an overseas criminal organization, though investigators have not ruled out human error during initial system configuration. The multi-day compromise occurred after several weeks of continuous cyberattack attempts directed at Renfe's networks, which the rail operator's defensive filters had previously detected and blocked.

Madrid
Spain

8 sources

  • Premieră periculoasă. Compania de trenuri folosită de mii de români, atacată cu ajutorul AI
    Mediafax.ro·1h ago
  • Après ses trains à grande vitesse défectueux, une cyberattaque dopée à l'IA frappe la compagnie ferroviaire publique espagnole
    BFMTV·2h ago
  • Atac cibernetic asupra operatorului feroviar spaniol Renfe, implicând AI. Datele unor utilizatori au fost compromise
    Ziare.com·2h ago
  • Espagne : la compagnie ferroviaire publique Renfe touchée par une cyberattaque - RTBF Actus
    RTBF·5h ago
  • Cyberattacco usando l'AI, rubati dati con l'intelligenza artificiale: attacco ad azienda ferroviaria
    Rai news·6h ago
  • Renfe sufre un ciberataque que compromete nombres y correos de usuarios, aunque matiza que el servicio se mantiene operativo
    El Periódico·15h ago
  • Renfe y Adif sufren un hackeo con IA que compromete información de los usuarios
    ABC TU DIARIO EN ESPAÑOL·15h ago
  • Un hackeo de 500 gigas golpea a Adif y Renfe
    La Razón·16h ago

Get Pollar Weekly

The week in news, every Friday. Free.

Free. No ads. Unsubscribe anytime.

More from Society & Science
Safety·from Sep 26·upd. 26m ago
© ANSA.it

Bangkok declares disaster zone across 50 districts as heavy flooding inundates streets

Bangkok authorities designated all 50 districts a disaster area after nearly 300 millimetres of rainfall flooded streets, displaced residents, and prompted the deployment of one million sandbags.

Read article
▶ Pollar film·editors' pick·2:45·Health & Education

FDA advisory panel narrowly endorses Grail's Galleri multi-cancer blood test

An FDA advisory panel voted 6-4 to affirm the effectiveness of Grail's Galleri screening, clearing a hurdle ahead of the agency's final decision.

recorded Sep 24

Safety·from Sep 22·upd. 57m ago

French court sentences far-right militants to 26 and 19 years for killing rugby star Aramburu

A Paris court sentenced former far-right group members Loik Le Priol and Romain Bouvier to 26 and 19 years in prison for the 2022 shooting of Argentine rugby international Federico Martin Aramburu.

Read article