ADIF A.I CyberSecurity Scoring
ADIF
Company Information
Website:http://www.adif.es/
Employees number:6,105
Number of followers:127,343
NAICS:482
Industry Type:Rail Transportation
Homepage:adif.es
ADIF Risk Score (AI oriented)
Between 700 and 749
ADIFRail Transportation
Updated:
01/10/2026
01/10/2026
701/1000
Moderate
Ba
ADIF Global Score (TPRM)
xxxx
ADIFRail Transportation
Score locked

ADIFModerate
Current Score
701Ba (MODERATE)
01000
2 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
701
SEPTEMBER 2026
720
Cyber Attack
24 Sep 2026 • ADIF
Renfe: Spain rail operator hit by cyberattack, user data compromised
Spanish Rail Operator Renfe Cyberattack Involving AI
701
CRITICAL-19
REN1790396731
Spanish Rail Operator Renfe Confirms Cyberattack Involving AI, Exposing User Data
Spanish state-owned railway operator Renfe disclosed a cyberattack that compromised user data, marking what local media reports as Spain’s first known AI-assisted breach targeting a public company. The incident, confirmed on Friday, originated from previously compromised servers belonging to railway infrastructure manager Adif, which were interconnected with Renfe’s systems.
The attack exposed limited user information, primarily names and email addresses, though Renfe stated there was no evidence the data had been publicly leaked. The company also confirmed that no financial details, payment methods, or sensitive identification documents were accessed. Despite the breach, rail services remained unaffected, following weeks of attempted attacks that had been successfully blocked.
Spanish daily El Mundo cited investigative sources claiming a criminal group used an AI system resembling Anthropic’s technology to target Adif’s website, which was temporarily unavailable. Reports indicated the breach lasted several days and resulted in the theft of approximately 500GB of data. While Renfe did not disclose the number of affected users or the exact timeline, La Razón suggested the attack bore the hallmarks of a foreign cybercriminal group.
The incident adds to growing global concerns over AI’s role in cyber threats, following a series of hacking incidents involving models from OpenAI and Anthropic. Security experts have warned of potential hybrid attacks, including cyber operations, amid heightened geopolitical tensions, particularly in relation to Russia’s ongoing invasion of Ukraine.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
719
JULY 2026
718
JUNE 2026
717
MAY 2026
716
APRIL 2026
715
MARCH 2026
714
FEBRUARY 2026
712
JANUARY 2026
711
DECEMBER 2025
710
NOVEMBER 2025
709
AUGUST 2024
772
Breach
22 Aug 2024 • ADIF
Renfe, Adif and ConnectWise: TCE Weekly Roundup: Renfe Breach, Hijacked AI Keys & Crime
Weekly Cybersecurity Roundup: AI as Target and Tool, Trusted Software Exploited in Attacks
687
CRITICAL-85
RENCONADI1790879055
Weekly Cybersecurity Roundup: AI as Target and Tool, Trusted Software Exploited in Attacks
This week’s cybersecurity incidents highlight two key trends: artificial intelligence (AI) as both a target and an attack vector, and threat actors abusing trusted software to evade detection.
### Key Incidents
Spain: Renfe Customer Data Breach via Compromised Partner Servers
On September 25, Spain’s national rail operator Renfe confirmed a data breach exposing customer names and email addresses. The attack originated from compromised servers belonging to Adif, the state-owned rail infrastructure manager. While no financial data or train services were affected, the incident underscores risks from third-party supply chain vulnerabilities.
Australia: Stolen AI Credentials Cost Firms Up to $600,000
The Australian Signals Directorate (ASD) warned that attackers are hijacking corporate AI services by stealing API keys, session tokens, and supplier access. Once inside, they drain paid credits, generate malicious content, and use AI agents to infiltrate connected systems. The financial impact has reached $600,000 per incident in some cases.
Poland: Patient Data Theft via Medical Software Vulnerability
Between August 22–23, attackers exploited an SQL injection flaw in Medyc, a Polish medical records platform developed by Qbusoft. The breach exposed patient names, national ID numbers (PESEL), addresses, and contact details dating back to July 2024. The intrusion went undetected for over two weeks, only discovered on September 8–9.
Global: Phishing Campaigns Abuse Legitimate Remote Management Tools
Microsoft tracked phishing campaigns tricking victims into installing MSP360, a legitimate remote management tool, disguised as Zoom downloads, Adobe updates, or delivery notices. After gaining access, attackers deployed ConnectWise ScreenConnect as a secondary persistence mechanism, blending malicious activity with routine IT operations.
Europe: Police Chiefs Warn of AI’s Role in Expanding Cybercrime
At Europol’s headquarters (September 28–30), over 500 police leaders from 59 countries discussed how AI is accelerating criminal operations. Threat actors are leveraging generative AI, deepfakes, and autonomous agents to scale fraud, cybercrime, migrant smuggling, and child exploitation. While AI also aids law enforcement investigations, its misuse is increasing the speed and scale of attacks.
### Emerging Threat Patterns
- AI as a Target & Weapon: Attackers are hijacking AI services for financial gain and lateral movement, while criminals use AI to enhance fraud and cybercrime.
- Abuse of Trusted Software: Legitimate tools from medical platforms to remote management software are being exploited to bypass security controls and maintain persistence.
- Supply Chain Risks: Breaches like Renfe’s demonstrate how vulnerabilities in third-party infrastructure can expose customer data.
These incidents reinforce the need for heightened scrutiny of AI credentials, remote access tools, and vendor security practices in enterprise environments.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ADIF ??
What was ADIF's A.I Rankiteo Cyber Score in September 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in August 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in July 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in June 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in May 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in April 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in March 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in February 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in January 2026 ??
What was ADIF's A.I Rankiteo Cyber Score in December 2025 ??
What was ADIF's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on ADIF's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ADIF ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ADIF's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?