A report published Sept. 27 put the Renfe–Adif cybersecurity incident at more than 150 million records. That is a reported record count, not a count of people affected. In its preliminary statement on Sept. 25, Renfe said attackers may have accessed limited user information, mainly names and email addresses.

What the reported number counts

A record is an entry in a dataset; a total of records does not give a headcount of distinct people. The report’s figure therefore describes the reported volume of records, not how many individuals were affected.

What Renfe said in its initial assessment

Renfe said technical indicators pointed to previously compromised Adif servers interconnected with Renfe systems as the suspected origin of the incident. Its Sept. 25 assessment described the user information as limited and mainly consisting of names and email addresses. Renfe said it activated its incident-response protocols, isolated affected environments and brought in independent cybersecurity specialists.

Rail service remained operational

Renfe said railway service continued to operate during the incident.