A September 27 report described a later forensic assessment that allegedly covered Renfe passenger identity details and named-ticket records—far more than the names and email addresses Renfe cited in its September 25 preliminary statement.
A later report describes a broader alleged exposure
The reported breakdown included about 20 million records with names and DNI numbers, Spain’s national identity-document numbers; about 20 million fuller identity records; and roughly 100 million named-ticket records. A separate figure in the reporting put the overall total above 150 million, while those three category estimates add up to about 140 million.
The fuller identity records were described as containing names, surnames, gender, phone numbers, email addresses, DNI numbers, birth dates and postal addresses. The reported figures and categories were attributed to a later forensic assessment.
What Renfe said on September 25
Renfe said its investigation was ongoing and that the information attackers may have accessed was limited, mainly consisting of customer names and email addresses. At that point, the company said it had no evidence of access to DNI numbers, banking or financial data, payment methods, or other especially sensitive information.
Renfe also said technical indications pointed to previously compromised Adif servers interconnected with Renfe systems as the suspected route into its systems.
What named-ticket records could connect
The reported ticket records could potentially link people with journeys. They were described as records associated with named tickets.
Renfe said rail service remained operational
In its September 25 statement, Renfe said rail service remained operational and guaranteed for passengers.