
Hackers steal 500 gigabytes of data from Spanish rail operator Renfe using AI tools
Spanish rail operator Renfe reported a data breach exposing passenger names and email addresses after attackers penetrated infrastructure manager Adif's systems using artificial intelligence tools.
Infiltration through interconnected railway networks
Spain's national passenger rail operator Renfe and rail infrastructure manager Adif experienced a multi-day cyberattack that compromised user records. The breach originated on the public web portal of Adif before attackers gained access to Renfe's connected cloud environment. Investigative sources cited by Spanish newspaper El Mundo reported that the attackers deployed an artificial intelligence framework similar to technology developed by Anthropic to target Adif's systems. The incident represents the first reported cyberattack utilizing artificial intelligence against the website of a Spanish public institution. Both state entities launched internal technical reviews, and Adif confirmed that its cybersecurity teams worked to contain the intrusion from the moment unusual activity surfaced.
Scope of user records and stolen files
Spanish media outlets reported that the perpetrators extracted approximately 500 gigabytes of data during the unauthorized intrusion. Renfe confirmed that attackers obtained limited user information, consisting primarily of passenger names and email addresses. Company officials stated that technical reviews found no evidence of compromised banking details, credit card numbers, payment methods, national identity document numbers (DNIs), or other sensitive personal records. Renfe also reported that no conclusive evidence indicates the stolen data has been published or distributed online. A company spokesperson declined to specify the total number of individuals affected by the breach or provide the exact date of the initial security failure.
Renfe issued a formal statement describing the countermeasures taken immediately after discovering the intrusion.
The origin of the attack lies in previously compromised Adif servers that maintained interconnection with the company's systems. The reaction was immediate. Response protocols were activated, affected environments were isolated, and extraordinary protection measures were deployed with the support of independent cybersecurity specialists.
Rail operations and passenger transport continuity
Passenger railway services across Spain continued to run on normal timetables without interruption during and after the attack. Renfe, which carried more than 531 million passengers during the previous year, confirmed that train operations, signaling systems, and critical transit controls remained isolated from the compromise. The public web portal of Adif remained inaccessible on Friday evening, 25 September 2026, as computer personnel and independent software contractors worked to restore online services. Adif stated that unusual activity was first registered in its systems late on Thursday, 24 September 2026, which investigators identified as the most critical phase of the incident. Renfe noted that the breach occurred despite holding high security certifications for critical infrastructure and making ongoing investments in threat monitoring.
- Renfe detects and blocks repeated cyberattack attempts against its internal networks.
- Adif detects unusual system activity during the most critical phase of the intrusion.
- Renfe confirms user data exposure as Adif takes its public web portal offline.
Official investigation and intelligence response
The incident was referred to the National Cryptologic Centre (CCN), a cybersecurity body attached to Spain's National Intelligence Centre (CNI). Adif filed a formal legal complaint regarding the intrusion and shared technical telemetry with partner companies and contractors that could be vulnerable to secondary attacks. Sources familiar with the inquiry cited by Spanish newspaper La Razon stated that the operational methods point toward an overseas criminal organization, though investigators have not ruled out human error during initial system configuration. The multi-day compromise occurred after several weeks of continuous cyberattack attempts directed at Renfe's networks, which the rail operator's defensive filters had previously detected and blocked.
