Plain News by AI Source-based international news without the spin.

Technology, AI & Cyber

Renfe cyberattack compromises names and emails

Spanish public railway company Renfe said on Friday that a cyberattack compromised limited user information, mainly names and email addresses, while rail services were running normally.

Renfe said the cybersecurity incident began on servers belonging to railway infrastructure manager Adif that had previously been compromised and were connected to Renfe systems. The company said it had no conclusive evidence that the accessed data had been made public.

Renfe said there was no evidence of access to bank or financial details, payment methods, IDs or other particularly sensitive information. A Renfe spokeswoman declined to say how many users were affected or when the breach happened.

Spanish daily El Mundo, citing sources close to the investigation, reported that a criminal organisation used a system similar to Anthropic's AI to attack Adif's website, and said it was the first AI cyberattack on the website of a Spanish public company. El Mundo and other outlets reported that criminals seized 500GB of data.

La Razon, citing sources with knowledge of the case, reported that the method pointed to a foreign group.

Uncertainty notes

Renfe did not say how many users were affected or when the breach happened.
Renfe said there was no conclusive evidence that the accessed data had been made public.
The reported use of AI, the reported 500GB data seizure and the reported foreign link are attributed to Spanish media reports rather than confirmed by Renfe.

Source

AFP news report published on .

Contact / Feedback

Send feedback, corrections or questions.