MediumII Cyber Warfare & Critical Infrastructure26 September 2026, Saturday
Attack that reached Renfe through Adif stole 500 GB of data
Attackers who entered through the website of Adif, one of Spain's 2 large public railway companies, moved into the systems of passenger operator Renfe. Reports published on 26 September say about 500 GB of data was stolen; Renfe says there is no evidence that payment or identity data was accessed.
In a statement on 25 September, Renfe said the attack originated on the servers of infrastructure manager Adif. According to the company, the attackers reached limited information, mainly names and email addresses; there is no evidence of access to payment, bank or ID number data. A Moncloa.com report dated 26 September said 500 GB of data was exfiltrated and that the extraction peaked on Thursday, 24 September. Both companies reported the incident to the National Cryptologic Centre (CCN) and the CNI intelligence service.
According to reports attributed to El Mundo, the attack unfolded in 3 steps: an AI system found a backdoor on Adif's website, moved from there into the corporate cloud and then into Renfe. Investigation sources cited by Moncloa.com suggest the method resembles a system used by a China-linked group against about 30 targets in November 2025, with AI doing 80–90% of the work. The AI claim and the 500 GB figure have not been confirmed by the companies, and the attacking group had not been identified as of 27 September. According to Merca2, no trains had stopped by that date and the websites were back to normal.
Adif was also hit in 2020 by an attack in which the REvil ransomware group stole 800 GB of data. The incident triggers the 24-hour notification deadline under Spain's implementation of the NIS2 directive, the EU rule that imposes cybersecurity obligations on critical infrastructure operators. According to Merca2, the AEPD data protection authority must also be notified within 72 hours under the GDPR.
Talay assessment
Bottom line
The attack did not halt rail operations, but 500 GB of passenger data and the claim of an AI-assisted intrusion show that the link between websites and internal systems is the weak point in public infrastructure. Since the figure and the method have not yet been confirmed by the companies, the most likely path is that the investigation narrows the scope of the leak while phishing risk persists for weeks.
Likely effects
- Passenger data and phishingNegativeWeeks
If names and email addresses were stolen, fake ticket and refund emails aimed at Renfe customers may increase in the coming weeks.
- EU critical infrastructure oversightUncertain1–6 months
The 24-hour notification deadline under NIS2 and the GDPR's 72-hour rule are forcing Spanish regulators to scrutinise 2 public companies at once.
- Debate on AI-assisted attacksNegative1–6 months
If the claim that AI did 80–90% of the work is confirmed, defence budgets for scanning exposed public websites in Europe will come onto the agenda.
Possibilities, ranked
- 1Leak stays limited55%
The investigation confirms the stolen data is limited to names and emails, and operations are unaffected.
Watch: An official statement on the incident from the CCN or the AEPD
- 2Data goes up for sale35%
A group claims responsibility and publishes part of the 500 GB on a leak site, widening the scope.
Watch: A Renfe or Adif listing on ransomware leak sites
- 3Operations are affected10%
A second wave of attacks disrupts ticket sales or traffic management systems.
Watch: A Renfe announcement of outages in ticket sales channels
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Data reported stolen▼ 500 GB
- Trains halted▲ 0
- AI share of work (claimed)▼ 80–90%