Breach tracker

Breach report

Spain's Renfe says a cyberattack through Adif systems exposed passenger data, and widens the scope to ID numbers

ConfirmedDisclosed Report published SpainOtherBy Vivek Kumar
Records UnknownCause Unknown

Spain's national rail operator says attackers came in through already-compromised servers of the rail infrastructure manager Adif. It first named names and emails, then added ID numbers, encrypted passwords and travel history.

What happened

Renfe, Spain's state rail operator, said it was investigating a cybersecurity incident that began on servers belonging to Adif, the rail infrastructure manager, which were connected to Renfe's systems and had already been compromised. The attack was dated 24 September. Renfe's first statement said names and email addresses of customers may have been affected, with no banking or payment data.

In a later statement reported on 28 September, Renfe widened the possible scope to DNI/NIE identity numbers, encrypted passwords, ticket details and travel history. Train services were not affected, and the incident was reported to Spain's cyber and data protection authorities.

Confirmed vs. claimed

Confirmed by Renfe, as reported: the incident, the entry through Adif systems and the types of data possibly affected. Not confirmed: media figures of around 500 GB and more than 150 million records attributed to a forensic report. Renfe has not given a number. No group has been named, and we have not repeated unsourced claims about how the attack was carried out.

Who is affected

People who bought Renfe tickets or held a Renfe account, including foreign travellers, some of them from India, who booked trains in Spain.

What to do

  • Change your Renfe password, and any other account where you used the same password.
  • Expect phishing about refunds, tickets or 'account verification' that uses your real name and trip details. Book and check only in Renfe's official app or website.
  • Never share OTPs or card details in response to a message or call about this incident.

Sources