CSIDB logo
Incident

Renfe

Incident posture

Attack window
Sep 2026
Location
Spain
Status
Unknown
CIA posture
Available to members
Updated
2026-09-28 21:50

Linked entities

Victim
Renfe
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

After detecting unusual activity on its systems, Adif reported that attackers had used previously compromised servers linked to Renfe’s network to access customer information, mainly names and email addresses. The operator confirmed the breach, isolated the affected environments, activated its response protocols and enlisted independent specialists, while noting no disruption to train services and no evidence that the data had been released. Adif took its websites offline temporarily, lodged a criminal complaint and informed Spain’s National Cryptologic Centre. The operator said it had been blocking repeated attack attempts for weeks before the incident and that the compromised data did not include bank details, payment methods or national‑identification numbers. Although claims of a 500 GB exfiltration and the use of artificial intelligence have circulated, neither organization has confirmed those details. No further impact on rail operations was reported.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Late on Thursday 24 September, Adif detected unusual activity on its systems. The following day Renfe stated that attackers used previously compromised Adif servers interconnected with Renfe systems to access customer information, mainly names and email addresses. Neither organization reported any effect on train services. As of 27 September, both organizations confirmed the detection, the origin via compromised Adif servers, and that the accessed data was a limited volume of Renfe customer information consisting primarily of names and email addresses, with no evidence of access to bank details, payment methods or national ID numbers. Renfe also said it had found no conclusive evidence that the information had been released.

Adif took the Adif and Adif Alta Velocidad websites offline as a precaution and restored them on Saturday 26 September. Adif lodged a criminal complaint, notified Spain's National Cryptologic Centre (CCN) and alerted companies and suppliers that may have been affected. Renfe isolated the affected environments, activated its response protocols and engaged independent specialists. Prior to the incident, Renfe had been blocking repeated attack attempts for several weeks. According to Adif, no system involved in running the railway was affected.

Adif and Renfe are successor entities of the former RENFE, split after the 2003 Railway Sector Act, and they routinely exchange information through service accounts, APIs, network tunnels, shared folders or replicated databases. The National Security Framework (ENS) requires prior authorization and documentation for such interconnections, and under Royal Decree 311/2022 Adif reported the incident to the CCN as required. El Mundo, quoting sources close to the investigation, reported that around 500 GB of data was taken and that investigators are examining whether the attackers used an AI system to identify the exploited weakness. Neither organization has confirmed these figures or the AI use, and the attack group remains unidentified. Open questions remain regarding the total volume taken, its exact content, the role of AI, the identity of the attackers and whether the data will appear publicly.

Sources

Sources available to members: 1 source.

CSIDB