Renfe and Adif hack: what was stolen and what to do if your data leaks

September 29, 2026 · JICA LABS

In late September 2026, attackers stole about 500 GB of data from Adif, Spain's railway infrastructure manager, and Renfe, the state train company. It is one of the largest data breaches in the country's history. If you have traveled by train in Spain, your data may be in it. And wherever you live, what follows applies: mass breaches are increasingly common.

What was stolen

Based on what has been reconstructed so far, the attackers used artificial intelligence to find a vulnerability at Adif and jumped from there to Renfe's portal. The incident was reported to Spain's National Cryptologic Center and intelligence service.

The real risk: tailor-made phishing

With no cards involved, the danger is not an emptied account tomorrow but a very convincing message. With your name, ID and last trip, a scammer can write: "Hi [your name], there was a problem with your Madrid–Valencia ticket on August 12, click here for a refund." That is the attack coming next.

What to do if your data leaks (anywhere)

  1. Distrust "official" messages. No serious company asks for passwords, codes or card details by email, SMS or WhatsApp. If in doubt, go to the official website or app yourself — never through the link in the message.
  2. Check whether your email appears in breaches on Have I Been Pwned, a free service.
  3. Change the password for affected accounts and anywhere you reused it. Better yet, use a password manager.
  4. Turn on two-step verification, ideally with an authenticator app rather than SMS.
  5. Watch your credit history for loans taken out in your name — your country's credit bureau or central bank registry usually offers a free report.
  6. If someone calls claiming to be your bank or the affected company, hang up and call the official number yourself.

Our take

This case combines two trends we have been covering: AI used for attacks and the sheer scale of data companies keep. Using AI to find the vulnerability shows attackers already automate what once took months of manual work. Personal defense remains the same, and it works: distrust, verify through the official channel and never reuse passwords. If you hold crypto, apply the same to your wallets: see wallets and security.

Sources

More notes