Particle.news

Renfe Data Breach Exposes Names and Emails Linked to Compromised Adif Servers

Spanish rail operators have filed a complaint and given evidence to the national cryptology centre for a technical probe of the intrusion

Overview

  • Renfe confirmed Friday that attackers accessed limited user contact records, mainly names and email addresses, after gaining entry through Adif servers that had been previously compromised.
  • Both companies say core rail operations and passenger services were not affected and train circulation continued to run normally during containment actions.
  • Renfe isolated the affected environments, activated its incident response protocols and hired independent cybersecurity specialists to help contain the intrusion.
  • Adif detected unusual activity late Thursday, has filed a formal complaint, shared its findings with the Centro Criptológico Nacional and notified suppliers that could be affected.
  • The breach follows weeks of probing attempts that security systems had partly blocked, raising a risk that exposed emails could be used in phishing campaigns and triggering regulatory notification and follow-up security audits.