Skip to content

Adif and Renfe cyberattack: is more AI the answer?

The Adif and Renfe cyberattack: what the data breach reports establish, how AI safeguards work, and how to protect a website with practical security controls.

Collage of a green railway loop with a protected section, a breach and the official Adif and Renfe logos on cream paper.
≈ 8:10

The cyberattack on Adif and Renfe raises an uncomfortable question: if artificial intelligence makes an attacker’s work cheaper, will businesses end up paying for another AI system to defend themselves?

The case deserves attention for its impact on passengers and for what it suggests about that race. It also needs careful reporting. Renfe’s initial statement and subsequent reporting by El Mundo describe different scopes. Although the newspaper reports AI involvement, the public evidence does not yet reconstruct how the attackers got in.

Adif and Renfe cyberattack: what is known about the data breach

On 25 September, Renfe confirmed a cybersecurity incident that technical indications traced to compromised Adif servers connected to its systems. The initial investigation pointed mainly to names and email addresses. The operator said it had no evidence of access to Spanish national identity numbers, bank details or payment methods, and that train services remained operational.

On 27 September, El Mundo reported a much larger breach: more than 150 million records, citing sources familiar with the forensic analysis. The newspaper described identity and contact information, including Spanish DNI numbers, and over 100 million named ticket records. Linking those datasets could reveal individuals’ journeys. The report also said there was no evidence of stolen banking or payment information.

The original El Mundo report on 25 September put the volume at 500 GB and reported that the attackers used AI. That is a newspaper’s account, not a figure included in Renfe’s statement.

More information is being shared on social media

On 28 September, Hackmanac posted an update about the scale of the theft and the alleged use of AI to identify vulnerabilities at Adif and progress towards Renfe. The thread links to El Mundo’s report.

Meanwhile, elhacker.NET shared on 25 September a screenshot of Adif’s website alongside the 500 GB figure reported by El Mundo.

Iterating with AI does not necessarily mean brute force

Brute force means trying many combinations, for example to guess a password. An agent that examines results and chooses its next check can follow a different process, adapting hypotheses and connecting findings.

The reporting we reviewed attributes AI assistance to this attack, but does not identify a model, publish its conversations or establish a technique that justifies calling it brute force. It also does not quantify how many decisions were human or autonomous. A general description should not become a definitive technical reconstruction.

The broader risk has an assessment independent of this incident. The UK NCSC’s outlook to 2027 expects AI to make parts of intrusions more efficient and increase the frequency and intensity of threats. It also expects tools to widen access to these capabilities.

Our interpretation is that cheaper investigation and automated repetitive work can enable more attempts against more targets. That does not establish that anyone with a few dollars can take down any website. Access, vulnerabilities, resources and defences still shape the outcome. Disrupting availability and extracting data are also different harms.

Anthropic’s safeguards are documented

has documented the routing of certain requests from to Opus. In its explanation of the Fable 5 redeployment, described classifiers that blocked certain requests and sent them to Opus 4.8. It also acknowledged that legitimate work could trigger the filters.

The policy has evolved. With Fable 5.1, announced in September, the company allows vulnerability discovery while retaining restrictions on exploit development and redirecting certain dual-use cybersecurity tasks to Opus. Such tasks can serve either defensive or offensive purposes.

These filters highlight a risk that extends beyond any one brand: the better AI becomes at finding vulnerabilities and connecting tasks, the more useful it can also be to attackers. Labs try to restrict that use while continuing to expand their models’ capabilities. That tension helps explain why safety concerns have led to calls for pauses in development.

The safety warnings were already on the table

In June, proposed the option of a coordinated, verifiable slowdown or pause in frontier model development. In When AI builds itself, it connects that proposal to progress towards systems capable of developing their successors and the risk of losing control. It also discusses the problem of stopping while others continue secretly.

On 18 August, OpenAI reported a two-week pause in reinforcement learning training for its latest models intended for deployment while it strengthened safeguards. Its announcement concerned risks observed in its own environments and ’s cybersecurity capabilities.

In June, a coordinated pause was proposed; in August, temporarily halted part of its training over safety risks; in September, El Mundo reported an AI role in the Adif and Renfe attack. That sequence gives the warnings a concrete dimension: capabilities that support legitimate work can also accelerate abuse. The NCSC expects threats to become more frequent and intense as these tools spread.

AI in cybersecurity: how to protect a website

AI can help review code, prioritise alerts and connect patterns across events. As an example of the approach, ’s August document describes using models to continuously test security boundaries against simulated attacks. That provider statement does not prove that every defensive product achieves the same results.

For a business running a website, we suggest starting with controls it can verify:

  • Keep an inventory of exposed services and patch known vulnerabilities. Software updates and multifactor authentication are part of CISA’s basic guidance.
  • Reduce privileges and separate systems to contain an intrusion. Pay particular attention to connections with suppliers and other applications.
  • Apply request limits and protection against abusive traffic. These help with repeated attempts but do not fix an authorisation flaw by themselves.
  • Keep useful logs and assign owners to alerts. A signal that nobody investigates offers little response capability.
  • Test restoration and prepare procedures for isolation, access revocation and incident communication.
Controls proposed by LetBrand. AI supports analysis on top of verifiable security foundations.

With those foundations in place, AI can accelerate analysis. A reasonable first use is reading minimised logs or reviewing changes and proposing actions, with restricted permissions and human review for decisions that could interrupt service or delete data. Attacker-controlled information in an alert must be treated as data, not as instructions for the agent.

We would measure detection and containment time, false positives and defects that survive review. Buying a tool because it has AI in its name does not establish that a website is better protected.

The circular race, and who gets paid

This is the tension that interests us at LetBrand. If AI reduces the cost of some offensive tasks and pushes defenders to automate more, demand for models and security services may rise. In that scenario, providers could earn revenue from defensive work addressing threats amplified by the technology itself.

That is a reasonable economic hypothesis. Claiming that companies requested a pause they knew would fail so they could sell more protection would require evidence of intent. The sources reviewed do not provide it. A commercial interest can coexist with a real security concern.

Our position is to ask for transparency about limitations, independent evaluations and measurable results. Defenders also need access to useful tools, and providers need accountability when they know of abuse patterns. A discussion of a pause should specify which activities would stop, who would verify compliance and how existing systems would remain protected.

The Adif and Renfe attack opens that discussion. For someone managing a website today, the immediate task is to check what a compromised account could reach, how long detection would take and whether the team can restore service. AI can help with that work; its results must be checked in the system being protected.

To apply that review to your product, tell us which system you use and what data it handles. We start with the scope and existing controls.