Administrador de Infraestructuras Ferroviarias
Incident posture
Linked entities
- Victim
- Administrador de Infraestructuras Ferroviarias
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Adif detected unusual activity on its systems and found that attackers had used previously compromised servers linked to Renfe’s infrastructure to access a limited amount of Renfe customer data, mainly names and email addresses, with no evidence of access to financial or identification details. The organization took its websites offline as a precaution, filed a criminal complaint and notified Spain’s National Cryptologic Centre, while Renfe isolated the affected environments, activated its response protocols and engaged independent specialists; both organisations confirmed that rail operations were unaffected and that there was no sign the data had been published.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Late on Thursday 24 September 2026 Adif detected unusual activity on its systems and immediately began an internal assessment. The following day Renfe disclosed that attackers had leveraged previously compromised Adif servers that were interconnected with Renfe’s infrastructure to access customer information, primarily names and email addresses. Neither organization reported any disruption to train services or to the systems directly responsible for railway operations. As a precaution Adif took the Adif and Adif Alta Velocidad websites offline on the evening of 24 September and restored them on Saturday 26 September after verifying that the precautionary measure was no longer needed. Adif also lodged a criminal complaint with the appropriate judicial authorities and notified Spain’s National Cryptologic Centre (CCN) of the incident in accordance with the National Security Framework requirements for public sector bodies. Renfe responded by isolating the affected environments, activating its established incident response protocols, and engaging independent specialists to support the investigation and remediation efforts.
As of 27 September the two organizations publicly confirmed that the compromised data consisted of a limited volume of Renfe customer information, mainly names and email addresses, with no evidence that bank details, payment methods or national identification numbers had been accessed. Renfe stated that it had found no conclusive indication that the exfiltrated data had been released or made publicly available. Prior to the detection Renfe had been blocking repeated attack attempts for several weeks, indicating that the threat actor had been probing the interconnected systems before achieving success. The confirmed impact on rail operations was explicitly stated by Adif to be none, as no systems involved in the management or control of train movements were affected.
Adif fulfilled its obligation under Article 33(2) of Royal Decree 311/2022 by informing the CCN and additionally alerted companies and suppliers that might have been impacted by the interconnection. Renfe’s internal response included the activation of its communication channels to keep stakeholders informed about the status of the investigation and the steps taken to secure the interconnected environments. The incident remains under investigation, with both organizations continuing to monitor for any further developments and cooperating with law enforcement and the CCN as required. No further details regarding the volume of data beyond the confirmed limited set, the specific tools or techniques used, or the identity of the attackers have been released by the involved parties.
Sources
Sources available to members: 1 source.