Renfe is investigating a cybersecurity incident that may have exposed the names and email addresses of customers after attackers compromised systems belonging to Spanish rail infrastructure operator Adif. The state-owned train operator says there is currently no evidence that banking details, payment information, DNI numbers or other particularly sensitive customer data were accessed. Train services have not been affected.
Renfe said the incident originated in previously compromised Adif servers that were interconnected with some of its own systems. Its preliminary investigation indicates that attackers may have obtained a limited amount of customer information, principally names and email addresses.
There is also currently no conclusive evidence that the information obtained has been published or distributed publicly, although Renfe says its investigation remains underway.
The company said it responded immediately by activating its cybersecurity protocols, isolating affected environments, and introducing additional protection measures with support from independent cybersecurity specialists.
Weeks of attempted attacks against Renfe
The breach comes after what Renfe describes as several weeks of continuous attempted attacks against its systems.
Those previous attempts had been detected and successfully blocked by the company’s security measures. Renfe has not identified who is responsible for the latest incident, and its investigation into the extent of the intrusion continues.
Adif detected unusual activity in its systems late on Thursday and began working to contain the attack and limit its potential impact. The infrastructure manager subsequently reported the incident and provided information to Spain’s Centro Criptológico Nacional, the national body responsible for cybersecurity affecting public-sector systems.
Companies and technology providers that may potentially have been affected have also been informed.
Are Renfe trains affected?
Despite the cybersecurity incident, rail operations have continued normally.
Adif says no application or computer system connected with railway operations was compromised, while Renfe says its train services remain operational and guaranteed for passengers.
Adif and Adif Alta Velocidad temporarily took their websites offline as a preventative security measure. Both were back online on Saturday after technical teams determined that their security had been restored.
The disruption to the websites should therefore not be confused with disruption to Spain’s rail network itself. Passengers have continued to travel while the cybersecurity investigation takes place.
What information may have been accessed?
Based on Renfe’s investigation so far, the information potentially accessed is limited mainly to:
- customer names
- email addresses
Renfe says there is no evidence at present that attackers obtained banking or financial information, payment methods, DNI numbers or other particularly sensitive personal data.
The distinction is important, but names and email addresses can still be valuable to criminals. They can potentially be used to make phishing emails and other fraudulent messages appear more convincing, particularly if a recipient recognises the name of a company with which they already have an account.
Customers should therefore be particularly cautious about unexpected messages claiming to come from Renfe or Adif and asking them to click a link, provide passwords or supply payment information.
Renfe has not said that such a phishing campaign is taking place as a result of this incident. The precaution is based on the type of information that may have been exposed rather than evidence that customers are already being targeted.
Investigation continues
Renfe says it maintains permanent investment in cybersecurity and monitoring because of its role as part of Spain’s critical infrastructure.
The company is continuing to strengthen its protective measures while working with the relevant authorities to establish exactly what happened and how much customer information may have been accessed.
For passengers, the immediate message is reassuring: trains are running normally and there is no evidence that payment or banking details were compromised.
However, anyone with a Renfe account should be wary of unexpected emails purporting to come from the rail operator while the investigation continues.