Skip to content

All the news that matters, in plain English.

Latest
  1. India delivers right of reply to Shehbaz Sharif's UNGA speech — warns "terrorism by Pakistan will have consequences"
  2. Pentagon HR breach exposed unencrypted personal data of up to 4 million US military personnel
  3. SpaceX lines up Crew-13 and Falcon Heavy NROL-97 on a same-day Oct 1 doubleheader
  4. Anti-migrant activist Daniel Thomas arrested on suspicion of criminal damage after Channel dinghy slashing
  5. US cities take on the FCC over its plan to override local broadband rules
  6. Glasgow City Council to sack and rehire more than 20,000 staff in pay row
  7. Judge declines to approve $110bn Paramount–Warner Bros merger settlement and demands more answers
  8. NHS staff to be suspended on the spot if suspected of snooping on patient records

Technology

Renfe confirms cyberattack exposed customer names and emails in suspected AI-assisted breach

Spanish rail operator Renfe said on Friday it suffered a cyberattack that compromised customer names and email addresses; El Mundo reports a criminal group used AI in what would be the first such attack on a Spanish public company's website.

Spanish state rail operator Renfe said on Friday it had suffered a cyberattack that compromised the names and email addresses of some customers, in what Spanish media report is the first AI-assisted attack on a Spanish public company’s website.

Renfe said the “cybersecurity incident” originated in servers of rail infrastructure manager Adif that had been “previously compromised and interconnected” with its own systems. The attackers accessed “limited user information, consisting mainly of names and email addresses”, the company said, adding there was “no conclusive evidence” the data had been made public and “no evidence” of access to bank or financial details, payment methods, IDs or other sensitive information.

The company said the breach followed “several weeks” of attempted attacks that had been “detected and successfully blocked”, and that rail services were running normally.

Spanish daily El Mundo, citing sources close to the investigation, reported that a criminal organisation used “a system similar” to Anthropic’s AI to attack Adif’s website — which was unavailable on Friday evening — describing it as the first AI cyberattack on a Spanish public company’s website, with the incident lasting “several days”. El Mundo and other outlets reported the criminals seized 500GB of data, a figure the company has not confirmed. La Razon reported that sources with knowledge of the case said the “modus operandi points to a foreign group”.

A Renfe spokeswoman declined to say how many users were affected or when the breach occurred.

Sources

More on this topic: all Technology stories

Get Flip News by email

This opens your email app — we add you manually. No account, no spam, no third parties.