Published on September 29, 2026 · The mitza.es team

Between Thursday 24 and Friday 25 September 2026, a security breach was detected in the digital infrastructure of Spain's rail infrastructure manager Adif and national rail operator Renfe. Both entities publicly confirmed the incident on 25 September, initially downplaying its severity. Forensic analysis revealed on Sunday 27 September uncovered the real scale: around 500 GB of stolen data, in what is already being described as the first major cyberattack using autonomous artificial intelligence against Spanish critical infrastructure.
Timeline of the attack
- 24-25 September: the intrusion is detected and both companies confirm the cyberattack, initially presented as limited in scope.
- 27 September: forensic analysis reveals the real scale of the theft: around 500 GB of data.
- 28-29 September: the emergency protocol is activated and the different blocks of affected data start being detailed.
What data was actually leaked
According to the forensic analysis, the stolen data breaks down into three main blocks, totalling over 150 million records:
- Low-risk data: around 20 million records with names and national ID numbers of Renfe website users.
- High-risk data: another 20 million records with first name, surname, sex, phone number, email, national ID, date of birth and postal address.
- Ticket-holder data: around 100 million records linking who bought which ticket.
Both Renfe and the forensic analysis agree that, so far, there is no evidence that banking data or payment details were accessed.
Why this attack is different
What sets this incident apart from others isn't just its scale, but how it was carried out. According to the first reconstructions of the attack, an artificial intelligence agent was used to autonomously find an access vulnerability on Adif's website, and from there pivot to Renfe's portal to extract the data. It is, according to the investigators themselves, the first documented case in Spain of this kind of attack against critical infrastructure carried out with autonomous AI at the vulnerability-discovery stage, not merely in sending phishing emails or generating malware.
What your SME should learn from this
Renfe and Adif are organisations with security resources far beyond those of a small business, and they still got breached. That's not a reason to relax, it's exactly the opposite: if an attacker can automate the search for vulnerabilities with AI, the cost of attacking smaller, worse-protected websites drops even faster. Some direct takeaways:
- An unpatched vulnerability no longer takes weeks to be found: it can take hours.
- Risk doesn't always come through your own website: it comes through the weakest connected provider or service in the chain.
- Downplaying severity in the first hours of an incident usually gets expensive once the full forensic analysis comes out later.
- Having a minimum incident response protocol, as required by the NIS2 directive, stops being paperwork the day you actually need it.
What to do if you have a Renfe account or manage business travel
If your business books train tickets regularly, it's worth reviewing account access and being extra cautious over the coming weeks: change your Renfe account password, enable two-factor verification if available, and be wary of emails or texts that cite real details from a recent ticket to appear legitimate. With real names, ID numbers and ticket data in the hands of third parties, the targeted phishing that follows tends to be far more convincing than usual.
How to find out if your own website is exposed
You don't need to run critical infrastructure to be a target: any website with an unpatched CMS, plugin or dependency is a potential door in. If you want to know what vulnerabilities your website has exposed right now, you can request a website security audit, and if you also need to review the general state of your equipment and access, our IT maintenance service includes a basic security review.