Spain’s national railway operator Renfe said it is investigating a cyberattack that appears to have originated from compromised ADIF servers, which are connected to Renfe’s systems.
What happened?
Technical indicators suggest that attackers accessed ADIF’s infrastructure, which had a network link to Renfe’s platforms, and then reached Renfe’s environment.
Did the attack disrupt train services?
Renfe confirmed that train operations and passenger services continued without interruption and that no timetable changes were reported.
What data may have been accessed?
The probe indicates possible unauthorized access to basic user information, though the scope is described as limited.
How is Renfe responding?
The company has launched a formal investigation, involving its own security team and external experts, and is working with authorities to assess the breach.
Is there any risk to passengers?
Renfe said there is no evidence that the incident affected ticketing, payment processing or the safety of train operations.
Renfe will provide updates as the investigation progresses and as more details become available.