Skip to content
AI-Driven Cyberattack Exposes Data of Spanish Railway Operators

AI-Driven Cyberattack Exposes Data of Spanish Railway Operators

First seen 28 Sep 2026, 18:19 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 19:12 UTC
  • •AI was used to automate the entire cyberattack on Adif and Renfe.
  • •Approximately 500GB of data was exfiltrated, including customer names and email addresses.
  • •The attack is under investigation by the Centro Criptológico Nacional (CCN-CERT).

On September 25, 2026, a cyberattack targeting Spain's railway operators Adif and Renfe led to the exfiltration of approximately 500GB of data. The attackers employed artificial intelligence to automate the attack, exploiting vulnerabilities in Adif's web infrastructure to gain access to Renfe's systems. Renfe confirmed that customer names and email addresses were compromised, but stated that no sensitive financial information was accessed. The breach is linked to prior unusual activity on Adif's network, which was detected and contained by the organization. The Centro Criptológico Nacional (CCN-CERT) is investigating the incident, which marks a significant escalation in AI-driven cyber threats against critical infrastructure. Both companies have activated incident-response measures and are cooperating with authorities to mitigate further damage.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-25
Cyberattack confirmed by Renfe
Renfe announced a cyberattack that compromised customer data, linking it to Adif's systems.
Thecyberexpress
2026-09-25
Adif detects unusual activity
Adif reported unusual activity on its network and implemented containment measures.
Thecyberexpress
2026-09-28
AI-driven attack reported
Rescana reported the use of AI in the cyberattack, marking a significant escalation in threats.
Rescana

More articles in this cluster (3)

Following this threat?

Track Play Ransomware Group, Apt40 and Adif in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed