Skip to main content
Defentria

Phishing and fraud

Renfe confirms passenger data was exposed in a cyberattack that began on Adif servers

Renfe has warned customers that unauthorised access to its systems may have exposed contact details, ID numbers, trips and encrypted passwords. It started on Adif servers connected to its network. If your company buys train tickets, this is the week to change passwords and warn your team.

By Defentria editorial teamPublished 4 min read

Renfe — Affected rail operator; the access originated on Adif servers connected to its network

Two Renfe AVE trains stopped alongside the platform at Seville Santa Justa station
Image: Savh on Wikimedia Commons (CC BY-SA 3.0, cropped)

In 30 seconds

  • Renfe confirms unauthorised access to its systems on 24 September. According to the company, it originated on previously compromised Adif servers connected to its network.
  • In its notice to those affected, Renfe lists identity and contact data, ID numbers, tickets and trips, and cryptographically protected passwords, and asks people to change their password as soon as possible.
  • Renfe says no banking data is affected and it has no evidence of fraudulent use. The immediate risk is fake emails, texts and calls that use this data.
  • The biggest figures (around 500 GB and more than 150 million records) come from El Mundo; Renfe has not confirmed them.

Does this affect me?

It affects you if anyone in your company has a Renfe account or buys tickets with company details, especially if they reuse that password for email or other work tools. And even if you don't travel by train, your team may receive scams impersonating Renfe that use real trip details.

What happened

On 25 September, Renfe announced it was investigating a cybersecurity incident originating on "previously compromised Adif servers that were interconnected with the company's systems". In that first statement it spoke of access to limited user information, mainly names and email addresses, and ruled out banking data and ID numbers.

Days later, Renfe published a notice on its website to the people affected that widens that assessment. According to the notice, on 24 September there was "unauthorised access to certain corporate systems" linked to ticket sales. The data that may have been exposed includes identity and contact information, tickets bought and trips taken, DNI or NIE numbers, and "authentication credentials (passwords), protected by cryptographic techniques".

Adif detected "unusual activity" on the night of Thursday the 24th, filed a complaint and said train services were not affected, according to Europa Press.

Renfe ticket machines in the hall of Príncipe Pío station in Madrid
Ticket sales at Príncipe Pío station (Madrid). According to Renfe, the access affected systems linked to its ticket sales processes. Image: Tim Adams on Wikimedia Commons (CC BY 3.0, cropped)

What we know

  • What data, according to Renfe: identity and contact data, tickets and trips, DNI or NIE numbers, and encrypted passwords. Renfe warns that a weak password could be cracked by brute force.
  • What not: banking data. Renfe's chairman, Álvaro Fernández Heredia, explained on 28 September that "banking data and credit cards are not stored in our system", according to Europa Press.
  • Use of the data: "to date we have no evidence that your data has been used fraudulently", says Renfe's notice.
  • Authorities: Renfe has informed the National Cryptologic Centre, the Guardia Civil and other cybersecurity bodies, and has notified the breach to the Spanish Data Protection Agency.

What we don't know yet

  • How many people are affected. Renfe has given no figures. El Mundo reports around 500 GB and more than 150 million records, including some 20 million with a name and ID number and more than 100 million named tickets, as reported by Hipertextual. Renfe has not confirmed those figures.
  • Whether the attackers used artificial intelligence, as several outlets report. Neither Renfe nor Adif has confirmed it.
  • What happened to the passwords. The messages don't match: Renfe's chairman said on 28 September that they had not been compromised, according to Europa Press, while the notice to those affected does include the credentials, encrypted, and asks people to change them. The sensible thing is to change them.
  • Who is behind it and whether the data has been published.

Why it matters

What matters is the type of data: not just names and emails, but also ID numbers and travel history. With that, a scammer can write a message that mentions a real trip, on a real date, in the name of the person who took it. That detail is what makes an impersonation convincing.

And the origin confirms a pattern: the access reached Renfe through another organisation's servers connected to its network.

Renfe logo
Renfe logo. Source: Wikimedia Commons (public domain)

What it means for an SME

Even if your company has nothing to do with trains, it's affected in two ways:

  • Your team are Renfe customers. If someone reuses their company email password, or the password of another work tool, on Renfe, someone else's breach becomes a way into your company.
  • Scams will be more convincing. An email saying "there's a problem with your Madrid–Seville ticket on the 12th" that gets the trip right is far more convincing than a generic one.

The underlying lesson applies to everyone: systems connected to suppliers and partners need the same vigilance as your own.

What your company should do this week

  1. Change the Renfe password on every account used to buy work tickets. If that password is reused on another service, change it there too, starting with email.
  2. Turn on two-step verification for email and critical tools, so a leaked password isn't enough to get in (guide to MFA, in Spanish).
  3. Warn your team that emails, texts or calls impersonating Renfe may arrive (refunds, compensation, problems with a ticket). The rule: never give out passwords, codes or bank details, and always check on the official website or app.
  4. If someone receives a suspicious message, they shouldn't reply or click, and should report it. INCIBE's 017 helpline answers cybersecurity questions free of charge.
  5. Review which suppliers are connected to your systems and what they can see. If there's no list, make one.

Sources

  1. Renfe — notice to the people affected by the cybersecurity incident (renfe.com, September 2026)Primary source
  2. Renfe — «Renfe investiga un incidente de ciberseguridad vinculado a Adif» (25 September 2026)Primary source
  3. Europa Press, in eldiario.es — «Renfe investiga un ciberataque a sistemas de Adif que filtró datos de usuarios» (25 September 2026)
  4. Europa Press, in Infobae — «Renfe asegura que los datos bancarios de sus clientes están a salvo tras el ciberataque» (28 September 2026)
  5. Hipertextual — «El hackeo a Renfe es peor de lo que todos pensaban» (28 September 2026)

Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.