Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
ADIF

ADIF Vendor Cyber Rating & Cyber Score

adif.es

Adif, el Administrador de Infraestructuras Ferroviarias, es una entidad pública empresarial dependiente del Ministerio de Transportes y Movilidad Sostenible. Ejercemos un papel principal como dinamizador del sector ferroviario, haciendo del ferrocarril el medio de transporte por excelencia y facilitando el acceso a la infraestructura en condiciones de igualdad. Tiene como objetivo potenciar el transporte ferroviario español mediante el desarrollo y la gestión de un sistema de infraestructuras seguro, eficiente, sostenible desde el punto de vista medioambiental, y con altos estándares de calidad. Adif asume: La administración de infraestructuras ferroviarias (vías, estaciones, terminales de mercancías, etc.) La gestión de la


ADIF A.I CyberSecurity Scoring

ADIF
Company Information
Website:http://www.adif.es/
Employees number:6,105
Number of followers:127,343
NAICS:482
Industry Type:Rail Transportation
Homepage:adif.es
ADIF Risk Score (AI oriented)
Between 700 and 749
logo
ADIFRail Transportation
Updated:
01/10/2026
701/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
ADIF Global Score (TPRM)
xxxx
logo
ADIFRail Transportation
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ADIFModerate
Current Score
701Ba (MODERATE)
01000
2 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
701Before Incident
SEPTEMBER 2026
720Before Incident
Cyber Attack
24 Sep 2026 • ADIF
Renfe: Spain rail operator hit by cyberattack, user data compromised

Spanish Rail Operator Renfe Cyberattack Involving AI

701After Incident
CRITICAL-19
REN1790396731
Spanish Rail Operator Renfe Confirms Cyberattack Involving AI, Exposing User Data Spanish state-owned railway operator Renfe disclosed a cyberattack that compromised user data, marking what local media reports as Spain’s first known AI-assisted breach targeting a public company. The incident, confirmed on Friday, originated from previously compromised servers belonging to railway infrastructure manager Adif, which were interconnected with Renfe’s systems. The attack exposed limited user information, primarily names and email addresses, though Renfe stated there was no evidence the data had been publicly leaked. The company also confirmed that no financial details, payment methods, or sensitive identification documents were accessed. Despite the breach, rail services remained unaffected, following weeks of attempted attacks that had been successfully blocked. Spanish daily El Mundo cited investigative sources claiming a criminal group used an AI system resembling Anthropic’s technology to target Adif’s website, which was temporarily unavailable. Reports indicated the breach lasted several days and resulted in the theft of approximately 500GB of data. While Renfe did not disclose the number of affected users or the exact timeline, La Razón suggested the attack bore the hallmarks of a foreign cybercriminal group. The incident adds to growing global concerns over AI’s role in cyber threats, following a series of hacking incidents involving models from OpenAI and Anthropic. Security experts have warned of potential hybrid attacks, including cyber operations, amid heightened geopolitical tensions, particularly in relation to Russia’s ongoing invasion of Ukraine.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Names and email addressesSystems Affected: Adif and Renfe interconnected systemsOperational Impact: Rail services remained unaffectedPayment Information Risk: None
DATA BREACH
Type Of Data Compromised: Personal data (names, email addresses)Sensitivity Of Data: Low (no financial or sensitive identification data)Data Exfiltration: Approximately 500GB of data stolenPersonally Identifiable Information: Names and email addresses
AUGUST 2026
719Before Incident
JULY 2026
718Before Incident
JUNE 2026
717Before Incident
MAY 2026
716Before Incident
APRIL 2026
715Before Incident
MARCH 2026
714Before Incident
FEBRUARY 2026
712Before Incident
JANUARY 2026
711Before Incident
DECEMBER 2025
710Before Incident
NOVEMBER 2025
709Before Incident
AUGUST 2024
772Before Incident
Breach
22 Aug 2024 • ADIF
Renfe, Adif and ConnectWise: TCE Weekly Roundup: Renfe Breach, Hijacked AI Keys & Crime

Weekly Cybersecurity Roundup: AI as Target and Tool, Trusted Software Exploited in Attacks

687After Incident
CRITICAL-85
RENCONADI1790879055
Weekly Cybersecurity Roundup: AI as Target and Tool, Trusted Software Exploited in Attacks This week’s cybersecurity incidents highlight two key trends: artificial intelligence (AI) as both a target and an attack vector, and threat actors abusing trusted software to evade detection. ### Key Incidents Spain: Renfe Customer Data Breach via Compromised Partner Servers On September 25, Spain’s national rail operator Renfe confirmed a data breach exposing customer names and email addresses. The attack originated from compromised servers belonging to Adif, the state-owned rail infrastructure manager. While no financial data or train services were affected, the incident underscores risks from third-party supply chain vulnerabilities. Australia: Stolen AI Credentials Cost Firms Up to $600,000 The Australian Signals Directorate (ASD) warned that attackers are hijacking corporate AI services by stealing API keys, session tokens, and supplier access. Once inside, they drain paid credits, generate malicious content, and use AI agents to infiltrate connected systems. The financial impact has reached $600,000 per incident in some cases. Poland: Patient Data Theft via Medical Software Vulnerability Between August 22–23, attackers exploited an SQL injection flaw in Medyc, a Polish medical records platform developed by Qbusoft. The breach exposed patient names, national ID numbers (PESEL), addresses, and contact details dating back to July 2024. The intrusion went undetected for over two weeks, only discovered on September 8–9. Global: Phishing Campaigns Abuse Legitimate Remote Management Tools Microsoft tracked phishing campaigns tricking victims into installing MSP360, a legitimate remote management tool, disguised as Zoom downloads, Adobe updates, or delivery notices. After gaining access, attackers deployed ConnectWise ScreenConnect as a secondary persistence mechanism, blending malicious activity with routine IT operations. Europe: Police Chiefs Warn of AI’s Role in Expanding Cybercrime At Europol’s headquarters (September 28–30), over 500 police leaders from 59 countries discussed how AI is accelerating criminal operations. Threat actors are leveraging generative AI, deepfakes, and autonomous agents to scale fraud, cybercrime, migrant smuggling, and child exploitation. While AI also aids law enforcement investigations, its misuse is increasing the speed and scale of attacks. ### Emerging Threat Patterns - AI as a Target & Weapon: Attackers are hijacking AI services for financial gain and lateral movement, while criminals use AI to enhance fraud and cybercrime. - Abuse of Trusted Software: Legitimate tools from medical platforms to remote management software are being exploited to bypass security controls and maintain persistence. - Supply Chain Risks: Breaches like Renfe’s demonstrate how vulnerabilities in third-party infrastructure can expose customer data. These incidents reinforce the need for heightened scrutiny of AI credentials, remote access tools, and vendor security practices in enterprise environments.
INCIDENT DETAILS -
TYPE
Data BreachCredential TheftPhishingSupply Chain AttackAI Exploitation
MOTIVATION
Financial GainData TheftLateral MovementFraudCybercrime Scaling
IMPACT
Financial Loss: $600,000 per incident (Australia)Customer names and email addresses (Renfe)Patient names, national ID numbers (PESEL), addresses, and contact details (Medyc)Renfe (via Adif servers)Medyc medical records platformCorporate AI services (API keys/session tokens)Remote management tools (MSP360, ConnectWise ScreenConnect)Undetected intrusion for over two weeks (Medyc)Abuse of legitimate IT tools for persistenceRenfeMedyc/QbusoftHigh (Poland: PESEL numbers exposed)
DATA BREACH
Customer names and email addressesPatient personal data (PESEL, addresses, contact details)High (PESEL numbers, medical records)NamesEmail addressesNational ID numbers (PESEL)AddressesContact details

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ADIF ?
?
What was ADIF's A.I Rankiteo Cyber Score in September 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in August 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in July 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in June 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ADIF's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ADIF's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on ADIF's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ADIF ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ADIF's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?