Thecyberexpress AI-Driven Cyberattack Exposes Data of Spanish Railway Operators
Article Content
- •AI was used to automate the entire cyberattack on Adif and Renfe.
- •Approximately 500GB of data was exfiltrated, including customer names and email addresses.
- •The attack is under investigation by the Centro Criptológico Nacional (CCN-CERT).
On September 25, 2026, a cyberattack targeting Spain's railway operators Adif and Renfe led to the exfiltration of approximately 500GB of data. The attackers employed artificial intelligence to automate the attack, exploiting vulnerabilities in Adif's web infrastructure to gain access to Renfe's systems. Renfe confirmed that customer names and email addresses were compromised, but stated that no sensitive financial information was accessed. The breach is linked to prior unusual activity on Adif's network, which was detected and contained by the organization. The Centro Criptológico Nacional (CCN-CERT) is investigating the incident, which marks a significant escalation in AI-driven cyber threats against critical infrastructure. Both companies have activated incident-response measures and are cooperating with authorities to mitigate further damage.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Play Ransomware Group, Apt40 and Adif in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…