Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cyberattack Hits Spanish Train Operator User Data

Spain’s largest train operator reported a cyberattack that compromised some usernames and email addresses, but the company said there’s “no evidence” that financial information was leaked. Spanish outlet El Mundo said the attack shared traces of AI, with the incident taking place amid warnings of intensifying Russian hybrid threats, though no signs pointed towards Moscow’s involvement at the time…

Cyberattack Hits Spanish Train Operator User Data

Spanish railway company Renfe disclosed that it fell victim to a cyberattack on Friday, resulting in unauthorized access to some user data. Media outlets hinted that the perpetrators employed AI technology, marking the first instance of such an attack in Spain. According to Renfe, the "cybersecurity incident" originated from servers of railway infrastructure manager Adif, which had previously been compromised and connected to Renfe's systems.

The attackers managed to access limited user information, primarily names and email addresses, but there is no clear evidence suggesting the data was disseminated. Renfe assured that no bank or financial details, payment methods, IDs, or other sensitive information were compromised. The incident followed several weeks of detected and thwarted attempted attacks.

Rail services continued to operate without disruption. Spanish newspaper El Mundo reported that a criminal organization utilized "a system similar" to Anthropic’s AI in the attack, which left Adif's website inaccessible for several days. This marks the first cyberattack by AI on a Spanish public company's website. Renfe did not disclose the number of affected users or the exact timing of the breach.

Reports suggest the criminals obtained 500GB of data. Experts warn that advanced AI tools are increasingly being exploited in cyberattacks, leading to heightened concerns about potential hybrid attacks on Western allies of Ukraine amid Russia's prolonged conflict.

Written by urgent.news from Kyiv Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at kyivpost.com →

More in Tech

RLS says yes and Postgres still says permission denied: the 403 family I only understood on the second one

RLS says yes and Postgres still says permission denied : the 403 family I only understood on the second one Read on: the layer of privileges RLS cannot reach at all · 繁體中文版 An admin tops up a…

  • RLS grants permission but admin still gets "permission denied" error
  • Admin role treated as authenticated when invoking PostgreSQL RPC
  • Wrap admin functions with SECURITY DEFINER to bypass GRANT restrictions

More from Saturday 26 September →