Overview
- Renfe confirmed Friday that attackers accessed limited user contact records, mainly names and email addresses, after gaining entry through Adif servers that had been previously compromised.
- Both companies say core rail operations and passenger services were not affected and train circulation continued to run normally during containment actions.
- Renfe isolated the affected environments, activated its incident response protocols and hired independent cybersecurity specialists to help contain the intrusion.
- Adif detected unusual activity late Thursday, has filed a formal complaint, shared its findings with the Centro Criptológico Nacional and notified suppliers that could be affected.
- The breach follows weeks of probing attempts that security systems had partly blocked, raising a risk that exposed emails could be used in phishing campaigns and triggering regulatory notification and follow-up security audits.