{
  "id": 9817643,
  "title": "Renfe investiga un ciberataque vinculado a sistemas de Adif que expuso datos básicos de usuarios",
  "url": "https://urgent.news/2026/09/25/renfe-investiga-un-ciberataque-vinculado-a-sistemas-de-adif-que",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-25T19:22:54.000Z",
  "source": {
    "name": "El Pais Economia",
    "slug": "el-pais-economia",
    "url": "https://elpais.com/economia/2026-09-25/renfe-investiga-un-ciberataque-vinculado-a-sistemas-de-adif-que-expuso-datos-basicos-de-usuarios.html"
  },
  "original_language": "es",
  "account": "Renfe, Spain's national railway company, is investigating a cyberattack linked to Adif's systems, which exposed basic user data. Technical clues suggest the breach originated from Adif servers that had previously been compromised and maintained interconnection with Renfe's systems. The public corporation maintains the attack did not disrupt train schedules or the provision of rail services. However, the investigation points to possible unauthorized access to limited user information, including names and email addresses. At present, there is no conclusive evidence that the data was disseminated publicly or that sensitive data, such as banking or financial information, was accessed. Renfe assures that no evidence of access to sensitive data, national ID documents, or other critical information has been found. The company emphasizes that the incident was limited and that essential systems for rail operations continue to function normally. Renfe activated its incident response protocols immediately upon detecting the issue, isolating potentially affected environments and deploying extraordinary protective measures, with the support of independent cybersecurity experts. The company, which holds the main security certifications and standards required for critical infrastructures, has invested continuously in cybersecurity. The internal investigation suggests a possible connection between the incident and previously compromised Adif systems. Adif confirmed detecting unusual activity in its systems late Thursday. Since then, its cybersecurity tools have worked to contain the suspicious activity, address the attacks, and limit their potential effects. Adif has reported the incident to the relevant authorities and made all collected data available to the National Cryptologic Center (CCN), the reference institution for cybersecurity in public administrations and strategic infrastructures in the country. Adif has also notified other companies and providers that might have been affected, enabling them to adopt necessary preventive and protective measures. The web outage of Adif is a visible consequence of the attack, affecting the website temporarily during the afternoon of this Friday. Renfe's web, however, remained operational. Both companies are conducting ongoing investigations to determine the origin, extent, and potential consequences of the incident. They insist on collaborating with specialists and competent authorities to clarify the facts and reinforce existing protection measures. This episode highlights the increasing pressure faced by critical infrastructures against growing cyberattacks against large public and private organizations.",
  "summary": "La compañía asegura que los atacantes solo pudieron acceder a nombres y correos electrónicos y que no existen indicios de filtración de datos bancarios ni de afectación al servicio ferroviario",
  "key_points": [
    "Renfe investigating cyberattack linked to Adif systems exposing basic user data.",
    "Technical clues suggest breach originated from previously compromised Adif servers.",
    "Investigation finds no evidence of sensitive data dissemination or rail service disruption."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}