Cyberattack hits Spanish train operator user data

Spanish public railway company Renfe on Friday said it had suffered a cyberattack that compromised some user data, with media reporting that criminals used AI in a first for Spain.
Renfe said in a statement that the “cybersecurity incident” originated in servers of railway infrastructure manager Adif that were “previously compromised and interconnected with the company’s systems”.
“The attackers were able to access limited user information, consisting mainly of names and email addresses,” but “no conclusive evidence” suggests the data was made public, Renfe said.
“There is no evidence of access to bank or financial details, payment methods, IDs or other particularly sensitive information,” added the company, which transported more than 531 million people last year.
Renfe said the incident came after “several weeks” of attempted attacks that had been “detected and successfully blocked” and that rail services were running normally.
Spanish daily El Mundo quoted “sources close to the investigation” as saying a criminal organisation used “a system similar” to Anthropic’s AI to attack Adif’s website, which was unavailable on Friday evening.
El Mundo said it was the first cyberattack by AI on the website of a Spanish public company, with the incident lasting “several days”.
A Renfe spokeswoman declined to say how many users were affected by the breach or when it happened.
The criminals seized 500GB of data, El Mundo and other outlets reported. According to La Razon, sources with knowledge of the case said “the modus operandi points to a foreign group”.
Global worries about the power of advanced AI tools are mounting after a string of hacking incidents involving models from ChatGPT developer OpenAI and its rival Anthropic.
Warnings have increased of possible hybrid attacks, including cyber incidents, on Western allies of Ukraine as Russia’s invasion grinds through its fifth year.

