Adif suffers a "sophisticated" cyberattack with possible information theft and access to suppliers

The railway manager detected the first incidents during the past weekend and has communicated the incident to the National Cryptological Center.

2 minutes

fotonoticia 20260918162044 1920

fotonoticia 20260918162044 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

2 minutes

Most read

Adif has suffered a "sophisticated" cyberattack that would have caused the theft of information from its systems and could have allowed access to the platforms of some of its suppliers, according to sources from the public company.

The railway infrastructure manager detected the first incidents during the past weekend and has since been working to analyze the scope of the attack and contain its effects. The company has confirmed that there was an intrusion into its systems, although it has not yet specified the exact volume of affected information.

According to the consulted sources, there is evidence that data has been extracted from Adif's systems, although at the moment there is no confirmation that this information has been published on the dark web.

The attack was reported to the National Cryptological Center

Adif has already reported the incident to the National Cryptological Center (CCN), the body responsible for the security of public administration systems and strategic entities.

The company plans to notify the Spanish Agency for Data Protection (AEPD) of the attack once the analysis of the compromised information progresses and it is determined whether personal data has been affected.

For now, there is no official figure on the amount of information stolen. Some sources suggest that the volume could be around 500 gigabytes of data, although this figure has not yet been confirmed by Adif.

Possible impact on suppliers

One of the main uncertainties of the attack is whether the intrusion would have also allowed access to external systems linked to the railway manager.

Company sources indicate that there is a possibility that the artificial intelligence used in the attack may have reached platforms of some Adif suppliers, although this aspect is still under investigation.

The incident occurs in a context of growing concern about attacks against strategic companies and public bodies, which in recent years have affected companies from various sectors.

Adif's website remains affected

As a consequence of the attack, Adif's website remained non-functional at the time of closing the information.

Additionally, some sources suggest that Renfe may also have suffered an attempted attack, although neither the railway company nor the Ministry of Transport has confirmed this circumstance at the moment.

The investigation remains open to determine the origin of the attack, the extent of the compromised information, and whether unauthorized access to third-party systems has occurred.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What functions does the National Cryptologic Center have in the protection of critical infrastructures in Spain?

The National Cryptologic Center (CCN), attached to the National Intelligence Center, is the State's main technical body in cybersecurity for the public sector and plays a key role in protecting critical infrastructures and entities in Spain, especially in their digital dimension. Its functions are articulated through the National Security Framework (ENS), the certification of ICT products and services, support for the transposition of the NIS2 Directive, and operational cooperation with other bodies such as the CNPIC/CNPREC and the Cybersecurity Coordination Office (OCC).

From a legal-organizational point of view, the CCN is regulated by Royal Decree 421/2004, of March 12, cited as a competence basis in various BOE resolutions on information technology security certification, where it is recognized the capacity to evaluate and certify the ICT security of development centers and laboratories (2025 resolutions). This certification function is integrated into the broader framework of national security policy, particularly in the protection of essential entities and services.

A central pillar of its contribution to the protection of critical infrastructures is the National Security Framework. According to the Generalitat Valenciana, the ENS is a regulatory and technical framework that sets the principles and requirements to guarantee information security in public administrations and their suppliers, and is "designed by the National Cryptologic Center (CCN) with the purpose of protecting sensitive and critical information that public administrations exchange among themselves, as well as with companies and citizens in general" (note from 03/30/2024). The ENS was thoroughly updated by Royal Decree 311/2022, raising security requirements, expanding the scope to private entities providing services to administrations, and establishing security categories (low, medium, high) particularly relevant for systems supporting critical services.

In practice, the CCN:

  • Defines and updates the technical requirements of the ENS that information systems of administrations and many providers supporting essential services must comply with.
  • Certifies compliance with the ENS, granting security certifications in categories such as “High ENS” to public entities and companies operating strategic infrastructures or services, which strengthens the protection of data and critical infrastructures.
  • Manages the ICT Security Products Catalog (CPSTIC) and includes qualified solutions suitable for high-level ENS systems, such as the secure communications platform COMSec by Indra, validated for high-criticality environments and “quantum resistant” communications (Demócrata, 07/14/2026).

Additionally, the CCN promotes the building of operational cybersecurity capabilities essential for the resilience of critical infrastructures. The National Network of Cybersecurity Operations Centers (SOC), coordinated by the CCN, integrates public SOCs and allows sharing cyberintelligence and early cyber threat alerts throughout the territory. The CCN itself is defining guidelines to enrich the information shared on this network with the goal of having a “complete and truthful overview of active cyber threats in Spain,” strengthening incident response in key sectors (note from 03/27/2024).

Regarding the NIS2 Directive and the new Spanish cybersecurity legislation, the Electronic Administration highlights that this Directive seeks to guarantee “a high common level of cybersecurity throughout the EU” and the resilience of critical infrastructures and digital services, imposing risk management and notification obligations on entities in essential sectors (08/05/2024). The CCN has enabled a specific consultation service (NIS2 mailbox and explanatory material) to help affected entities comply with these obligations, positioning the body as a technical reference for adapting critical infrastructures to the new European requirements.

The relationship with the National Center for the Protection of Critical Infrastructures (CNPIC), renamed as the National Center for the Protection and Resilience of Critical Entities (CNPREC) in the Critical Entities Protection and Resilience Law project approved by the Government in 2026, is mainly one of functional complementarity. The Interior Ministry emphasizes that the State Secretariat for Security, through the CNPREC, will be the national competent authority in identifying and protecting critical entities and in preparing national, sectoral, and operational support plans (note from 03/17/2026). While the CNPIC/CNPREC handles the cataloging, planning, and coordination of the physical and organizational protection of these entities, the CCN provides the technical framework and cybersecurity capabilities necessary to ensure the confidentiality, integrity, and availability of the information systems supporting those essential services.

This cooperation is visible in specific arrangements: in special security operations, Interior has indicated that the CNPIC maintains contact with critical service operators while the Cybersecurity Coordination Office (OCC), “in collaboration with the National Cryptologic Center,” strengthens protection against cyber threats on those same infrastructures (03/11/2025). The combination of: (1) sectoral authority over critical entities (CNPREC), (2) ENS framework and CCN certifications, and (3) new cybersecurity legislation transposing NIS2 and “shielding critical infrastructures” (Demócrata, 09/22/2026) configures the ecosystem in which the CCN plays an essential, although predominantly technical and cybersecurity, role in protecting critical infrastructures in Spain.

Can you detail what the National Security Framework requires from entities managing essential or critical services? How does the CNPREC coordinate with the CCN and with the future Cybersecurity Law transposing the NIS2 Directive? What practical impact does being included in the CCN's ICT Security Products Catalog have for a company in terms of access to critical infrastructure contracts?

What is the professional background of the president of Adif and to which political party is he linked?

The current president of Adif (Railway Infrastructure Manager) and Adif High Speed is Luis Pedro Marco de la Peña —often abbreviated in many reports as Pedro Marco or Pedro Marco de la Peña—. He was appointed by the Council of Ministers on September 17, 2024, as the top official of the public railway manager.

According to the official note from the Ministry of Transport and subsequent resolutions in official bulletins, Marco de la Peña was born in Santander in 1969 and is a Civil Engineer from the University of Cantabria, a degree he obtained in 1993. His profile is built on a combination of prolonged experience in the private civil works sector and a relevant stage in the public sector, especially in the Basque railway field and later in the State administration.

His professional career in the private sector began in 1994, when he joined Ferrovial, where he worked for five years on construction and infrastructure projects. After this stage, he moved to the company Construcciones Amenabar and, over time, assumed managerial responsibilities in several companies in the sector:

  • Construcciones Amenabar, where he performed management functions and ended up as managing director.
  • Exbasa Obras y Servicios, where he appears as manager, linked to civil works projects.
  • Construcciones Balzola, where he served as director of Civil Works and Railways, reinforcing his specialization in railway infrastructures.
  • Construcciones Fhimasa and i-INGENIA Ingeniería y Arquitectura, companies where he reached the position of general director.

These positions show a trajectory of more than a decade in construction and engineering companies, linked to public works contracts, railways, and mobility projects, before moving to the administration.

In 2009 he began his stage in the public sector, when he was appointed general director of Euskal Trenbide Sarea (ETS), the Basque Government's public entity in charge of the regional railway network. He remained in this position until 2013, during a period in which ETS consolidated its role as a railway infrastructure manager in Euskadi and coordinated relevant network modernization projects.

His link with the Basque administration was reinforced again from 2020, when he assumed the position of Deputy Minister of Infrastructure and Transport of the Basque Country. From that position, according to official information, he holds responsibilities over a broad set of public operators and managers:

  • Basque Railway Network / ETS and Basque Railways (Eusko Trenbideak), responsible for much of the regional railway transport.
  • Metro Bilbao, one of the main urban transport systems in the Bilbao metropolitan area.
  • Ports of Bilbao and Pasajes, state-owned but closely linked to Basque infrastructure policy.
  • Logistics platforms such as Zaisa (Irún), Aparkabisa (Barakaldo), and the Vitoria Transport Center (CTV).
  • The Bizkaia Transport Consortium (CTB) and transport in Euskadi as a whole, including the three historical territories.

This stage places him as one of the key officials in the planning and management of transport infrastructures in Euskadi, with a special focus on railways and intermodality.

The jump to the presidency of Adif and Adif High Speed occurred in September 2024, when the Council of Ministers approved his appointment at the proposal of the then Minister of Transport and Sustainable Mobility, Óscar Puente. Various subsequent resolutions (including addenda and agreements signed by Adif and published in official bulletins) expressly refer to him as “president of the Public Business Entity Railway Infrastructure Manager (Adif)” and of Adif High Speed, acting on behalf of both entities in agreements with other administrations.

Since his arrival at the presidency, his name has appeared recurrently in political and economic news linked to three major blocks: the management of the high-speed network, railway incidents and accidents —particularly the Adamuz (Córdoba) accident— and debates on reliability, maintenance, and investments in the network. He has appeared both in the Congress and the Senate in investigative and Transport committees, and his management has been subject to union criticism and some political groups, which have occasionally called for his resignation.

Regarding his link with political parties, the institutional and journalistic sources consulted (including the official note of his appointment and profiles mentioned in the press) do not record membership, organizational positions, or an explicit public affiliation to a specific party. He is mainly presented as a technical profile, specialized in infrastructures and railway management, coming from the engineering sector and infrastructure administration in Euskadi. Therefore, with the available information, it cannot be rigorously stated that he is officially linked to a specific political party beyond having been appointed by governments of a certain political orientation.

What specific responsibilities does the president of Adif have regarding the safety and maintenance of the railway network? How has Luis Pedro Marco de la Peña responded in his parliamentary appearances to criticisms about the Adamuz accident? What differences were there between the management of the previous Adif president, Isabel Pardo de Vera, and that of Luis Pedro Marco de la Peña?

What legal requirements must be met to notify a security breach to the Spanish Data Protection Agency?

The obligation to notify a security breach to the Spanish Data Protection Agency (AEPD) mainly derives from Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD). It is not an "optional" notification: it is a legal duty subject to very strict deadlines and specific content requirements.

1. When there is an obligation to notify the AEPD

Any personal data security breach that may pose a risk to the rights and freedoms of natural persons must be notified to the AEPD. This includes, for example:

  • Unauthorized access (hacking, sending information to a wrong recipient, loss of devices with unencrypted data).
  • Accidental or unlawful alteration or destruction of personal data.
  • Prolonged unavailability of systems that prevents the exercise of rights or the provision of essential services.

If, after a reasoned assessment, it is concluded that the breach is unlikely to cause a risk (for example, strongly encrypted data without realistic possibility of decryption), there is no obligation to notify the AEPD, but it must be documented internally (breach register).

2. Who must notify and within what timeframe

The obligation to notify falls on the data controller. The data processor (provider processing data on behalf of the controller) must, in turn, communicate without undue delay to the controller any security breach of which it becomes aware.

The controller must notify the AEPD without undue delay and, if possible, no later than 72 hours after becoming aware of the breach. If the notification is made after that deadline, the delay must be expressly justified.

3. Channel and form of notification

Notification is usually made through the AEPD's electronic headquarters, using the specific form for "Notification of personal data security breaches." In practice, for most organizations, notification is done electronically with the digital certificate of the controller or its representative.

In cross-border contexts (when processing affects data subjects in several Member States), the lead supervisory authority must be determined. If the controller's main establishment is in Spain, or the main impact occurs on data subjects in Spain, the AEPD will act as the competent authority.

4. Minimum content of the notification

The GDPR requires that the notification to the AEPD be, at minimum, detailed enough to understand the incident and assess the measures taken. It must include, among other elements:

  • Description of the nature of the breach of security, indicating, when possible:
    • Categories of data affected (identifiers, financial, health, etc.).
    • Categories of data subjects affected (clients, employees, web users, etc.).
    • Approximate number of data subjects and records affected.
  • Contact details of the data protection officer (DPO) or another contact person for further information.
  • Description of possible consequences of the breach (risk of fraud, identity theft, discrimination, reputational damage, economic loss, etc.).
  • Description of measures taken or proposed to:
    • Contain the breach (e.g., system disconnection, credential revocation).
    • Mitigate its possible effects on data subjects (account monitoring, specific recommendations, etc.).
    • Prevent its recurrence (strengthening technical and organizational measures, procedure reviews, training, etc.).

When it is not possible to provide all information from the outset, the controller may make a staggered notification, providing available data within 72 hours and completing the information later, without undue delay.

5. Obligation to document all breaches

Even when it is concluded that the breach does not reach the risk threshold that requires notification to the AEPD, the GDPR requires the controller to document internally all security breaches. This register must record:

  • Facts related to the breach (what happened and when it was detected).
  • Its potential or actual effects.
  • Corrective measures adopted.

This register is essential to demonstrate compliance with the principle of proactive accountability before the AEPD itself.

6. Relation with communication to affected individuals

In addition to notification to the AEPD, when the breach poses a high risk to the rights and freedoms of individuals, the controller must also communicate it to the affected individuals, in clear and simple language. This communication must include, comprehensibly, the nature of the breach, possible consequences, and measures taken or recommended. The existence of this obligation and how it is fulfilled may also be assessed by the AEPD when examining the notification.

How should the communication of a security breach to affected individuals be and in which cases is it mandatory? What sanctions can the AEPD impose if a security breach is not properly notified? What practical steps should a company follow from detecting a security breach until notifying it?

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What direct consequence did the cyberattack have on Adif's website?

Question 1 of 3

Which organization received the incident notification from Adif?

Question 2 of 3

What is one of the main questions still under investigation after the cyberattack on Adif?

Question 3 of 3