Adif has suffered a "sophisticated" cyberattack that would have caused the theft of information from its systems and could have allowed access to the platforms of some of its suppliers, according to sources from the public company.
The railway infrastructure manager detected the first incidents during the past weekend and has since been working to analyze the scope of the attack and contain its effects. The company has confirmed that there was an intrusion into its systems, although it has not yet specified the exact volume of affected information.
According to the consulted sources, there is evidence that data has been extracted from Adif's systems, although at the moment there is no confirmation that this information has been published on the dark web.
The attack was reported to the National Cryptological Center
Adif has already reported the incident to the National Cryptological Center (CCN), the body responsible for the security of public administration systems and strategic entities.
The company plans to notify the Spanish Agency for Data Protection (AEPD) of the attack once the analysis of the compromised information progresses and it is determined whether personal data has been affected.
For now, there is no official figure on the amount of information stolen. Some sources suggest that the volume could be around 500 gigabytes of data, although this figure has not yet been confirmed by Adif.
Possible impact on suppliers
One of the main uncertainties of the attack is whether the intrusion would have also allowed access to external systems linked to the railway manager.
Company sources indicate that there is a possibility that the artificial intelligence used in the attack may have reached platforms of some Adif suppliers, although this aspect is still under investigation.
The incident occurs in a context of growing concern about attacks against strategic companies and public bodies, which in recent years have affected companies from various sectors.
Adif's website remains affected
As a consequence of the attack, Adif's website remained non-functional at the time of closing the information.
Additionally, some sources suggest that Renfe may also have suffered an attempted attack, although neither the railway company nor the Ministry of Transport has confirmed this circumstance at the moment.
The investigation remains open to determine the origin of the attack, the extent of the compromised information, and whether unauthorized access to third-party systems has occurred.