Renfe Viajeros (Renfe Passengers) wishes to inform you of a cybersecurity incident that has affected certain information systems and may have compromised personal data associated with the use of its services.
What happened?
Renfe Viajeros (Renfe Passengers) has detected unauthorised third-party access to certain corporate systems. According to investigations carried out, our systems were accessed on 24 September 2026. The incident was identified through our internal monitoring and anomalous activity detection mechanisms. From the moment it was detected, the planned response and containment procedures were activated immediately, limiting access and deploying additional security measures.
Investigations carried out indicate that the unauthorised third party may have accessed certain systems related to ticket sales processes. However, the investigation is still ongoing to determine the full scope of the incident and to verify whether other categories of data may have been affected.
What data may have been affected?
According to the information currently available, the potentially compromised data may include identification and contact information, as well as information associated with the use of Renfe services, including information relating to purchased tickets and trips made. Likewise, the potentially affected information could include National ID Document numbers, Tax ID codes or other equivalent ID document information, as well as authentication credentials (passwords), which are protected by cryptographic security techniques that prevent them from being read directly.
Associated risks
Although we have no evidence that your data has been used fraudulently as a result of this incident, there is a risk that third parties may attempt to:
- Conduct phishing or impersonation campaigns using illicitly obtained personal information.
- Send fraudulent e-mails, SMS messages or make fraudulent calls purporting to be from Renfe or other legitimate organisations.
- Attempt to obtain login credentials, bank details or other personal information through social engineering techniques.
- Analyse or infer information relating to journeys, routes taken or usage patterns of railway services from information associated with tickets and trips, potentially generating profiles or behaviour patterns of certain people.
- If any of the passwords associated with the affected credentials are particularly weak, there is a risk that they could be obtained through brute-force decryption techniques, potentially allowing unauthorised access to services that use the same password.
What measures do we recommend you take?
We recommend that you exercise extreme caution in response to any unexpected communication requesting personal information, access credentials or bank details. In particular:
- Do not share passwords, verification codes or bank details via e-mail, messages or phone calls.
- Carefully verify the sender and authenticity of any communication claiming to be from Renfe. Exercise particular caution with communications that include references to completed journeys, bookings, incidents or supposed financial compensation, even if they appear to come from legitimate organisations. In the event of any unexpected request for personal or financial information, use official channels to verify its authenticity before providing any information or taking any action.
- If you have a registered user account, we recommend that, for greater security, you change your password as soon as possible. If you use the same password on other services, we recommend that you change it on those services as well.
- Be vigilant for any unusual activity related to your accounts or personal data, and immediately report any incident you detect to the relevant entity.
You can find more cybersecurity tips and recommendations in the following INCIBE publication.
What measures has Renfe taken?
Since the incident was detected, the following measures have been taken, among others:
- Immediate activation of internal incident response protocols;
- Enhanced containment and monitoring of affected systems;
- Forensic investigation to determine the scope and origin of the incident;
- Request for preservation and delivery of evidence to the external providers and repositories involved;
- Reporting the incident to the competent cybersecurity authorities (CCN, OCC), critical infrastructure authorities (CNPIC) and the Civil Guard;
- Notification of the security breach to the Spanish Data Protection Agency (AEPD);
- Implementation of additional technical and organisational measures to strengthen the protection of our systems and reduce the risk of similar incidents.
Additional information
We deeply regret any inconvenience this situation may have caused and reiterate our commitment to protecting your personal data.
For further information, you can contact the Data Protection Officer at the following address: dpdviajeros@renfe.es