Renfe analyzes a cyberattack on Adif systems that exposes private data but not IDs or payment methods.

Renfe and Adif are investigating a cyberattack that exposed contact data of travelers, without affecting IDs, payment methods, or railway circulation.

1 minute

fotonoticia 20260925210431 1920

fotonoticia 20260925210431 1920

Add DEMÓCRATA to Google

Ask FREN

Published

1 minute

Most read

Renfe has initiated a technical investigation this Friday following a "cybersecurity incident" linked to the extraction of traveler data, whose origin is located in previously compromised Adif servers connected to the networks of the railway operator.

In a statement, the company details that the initial analyses indicate that the attackers accessed a "limited" amount of customer information, mainly focused on names and email addresses, without any banking or financial information being compromised.

The public company emphasizes that its response has been "immediate," activating internal protocols, isolating the affected environments, and deploying extraordinary containment measures with the support of external cybersecurity experts.

The investigation remains open, but Renfe has ruled out that payment methods, ID numbers, or other especially sensitive data have been stolen. Furthermore, there is no evidence that this information has been disseminated in public spaces.

"Renfe has the highest certifications and security standards applicable to critical infrastructures and maintains ongoing investments in cybersecurity, monitoring, and protection of its systems. The company continues to strengthen these measures and collaborate with the competent authorities to clarify the facts," the entity has stated.

This incident occurs after several weeks of repeated attempts of cyberattacks against Renfe's technological infrastructure, which had so far been neutralized by its defense systems.

Adif's response to the incident

Adif, for its part, has communicated that it detected "unusual activity" in part of its systems on Thursday night, after which its cybersecurity teams began to work to halt the attack and minimize its effects.

As the entity has specified, "No application or system related to railway operations has been affected. Railway circulation is guaranteed and is proceeding under normal conditions."

The railway network administrator has filed the corresponding complaint and has informed the National Cryptologic Center (CCN) about the case. Additionally, it has alerted potentially affected companies and providers to adopt the necessary protective measures.