Spain’s main train operator Renfe says it suffers a cyberattack that compromises some users’ data. The company reports that the breach affects certain usernames and email addresses, and it says there is “no evidence” that payment or financial information was leaked.

Different outlets report additional details about how the attack is conducted. Spanish media, including El Mundo, says criminals used artificial intelligence, describing the event as a first for Spain. Both reports frame the incident as part of a broader backdrop of heightened cyber and “hybrid” threats, though the available information does not point to any specific state actor. At the time of publication, no public evidence links the attack to Russia or other governments, and Renfe’s statement emphasizes the limited scope of the exposed data.

Authorities and the operator continue to assess the impact and whether any further information was accessed, while users are affected primarily through compromised account identifiers rather than financial data.