← Renfe

2026 Renfe — customer names/emails via Adif interconnected systems compromise

2026 Unknown records affected Share on X

Data compromised

Per Renfe: primarily customer names and email addresses. No evidence so far of banking/financial info, payment methods, identity documents, or other sensitive data. No conclusive evidence of public distribution. Railway operations systems not affected. Census unpublished.

Technical writeup

Verified operator disclosure — Renfe investigating a cybersecurity incident that exposed some customer information (FTN News / trade coverage Sep 27, 2026). Attackers primarily accessed names and emails; Renfe found no evidence banking, payment methods, ID documents, or other sensitive data were accessed; no conclusive public dump. Investigation points to previously compromised Adif systems interconnected with Renfe. Adif detected unusual activity late Thursday, contained, filed complaint, and briefed Spain’s National Cryptologic Center (CCN); Adif website briefly unavailable Friday afternoon. Train services unaffected. Earlier intrusion attempts against Renfe reportedly detected/blocked. recordsAffected 0; companyConfirmed true.

Root cause

Attackers accessed Renfe customer data after compromise of interconnected Adif systems (Renfe/Adif disclosures; late Sep 2026)

References