Renfe, Adif and ConnectWise: TCE Weekly Roundup: Renfe Breach, Hijacked AI Keys & Crime

Renfe, Adif and ConnectWise: TCE Weekly Roundup: Renfe Breach, Hijacked AI Keys & Crime

Weekly Cybersecurity Roundup: AI as Target and Tool, Trusted Software Exploited in Attacks

This week’s cybersecurity incidents highlight two key trends: artificial intelligence (AI) as both a target and an attack vector, and threat actors abusing trusted software to evade detection.

Key Incidents

Spain: Renfe Customer Data Breach via Compromised Partner Servers
On September 25, Spain’s national rail operator Renfe confirmed a data breach exposing customer names and email addresses. The attack originated from compromised servers belonging to Adif, the state-owned rail infrastructure manager. While no financial data or train services were affected, the incident underscores risks from third-party supply chain vulnerabilities.

Australia: Stolen AI Credentials Cost Firms Up to $600,000
The Australian Signals Directorate (ASD) warned that attackers are hijacking corporate AI services by stealing API keys, session tokens, and supplier access. Once inside, they drain paid credits, generate malicious content, and use AI agents to infiltrate connected systems. The financial impact has reached $600,000 per incident in some cases.

Poland: Patient Data Theft via Medical Software Vulnerability
Between August 22–23, attackers exploited an SQL injection flaw in Medyc, a Polish medical records platform developed by Qbusoft. The breach exposed patient names, national ID numbers (PESEL), addresses, and contact details dating back to July 2024. The intrusion went undetected for over two weeks, only discovered on September 8–9.

Global: Phishing Campaigns Abuse Legitimate Remote Management Tools
Microsoft tracked phishing campaigns tricking victims into installing MSP360, a legitimate remote management tool, disguised as Zoom downloads, Adobe updates, or delivery notices. After gaining access, attackers deployed ConnectWise ScreenConnect as a secondary persistence mechanism, blending malicious activity with routine IT operations.

Europe: Police Chiefs Warn of AI’s Role in Expanding Cybercrime
At Europol’s headquarters (September 28–30), over 500 police leaders from 59 countries discussed how AI is accelerating criminal operations. Threat actors are leveraging generative AI, deepfakes, and autonomous agents to scale fraud, cybercrime, migrant smuggling, and child exploitation. While AI also aids law enforcement investigations, its misuse is increasing the speed and scale of attacks.

Emerging Threat Patterns

  • AI as a Target & Weapon: Attackers are hijacking AI services for financial gain and lateral movement, while criminals use AI to enhance fraud and cybercrime.
  • Abuse of Trusted Software: Legitimate tools from medical platforms to remote management software are being exploited to bypass security controls and maintain persistence.
  • Supply Chain Risks: Breaches like Renfe’s demonstrate how vulnerabilities in third-party infrastructure can expose customer data.

These incidents reinforce the need for heightened scrutiny of AI credentials, remote access tools, and vendor security practices in enterprise environments.

Source: https://thecyberexpress.com/weekly-roundup-renfe-breach-ai-keys/

Renfe cybersecurity rating report: https://www.rankiteo.com/company/renfe

ConnectWise cybersecurity rating report: https://www.rankiteo.com/company/connectwise

ADIF cybersecurity rating report: https://www.rankiteo.com/company/adif

"id": "RENCONADI1790879055",
"linkid": "renfe, connectwise, adif",
"type": "Breach",
"date": "8/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Unknown (names and email '
                                              'addresses exposed)',
                        'industry': 'Transportation',
                        'location': 'Spain',
                        'name': 'Renfe',
                        'type': 'National Rail Operator'},
                       {'customers_affected': 'Renfe customers (via '
                                              'compromised servers)',
                        'industry': 'Transportation/Infrastructure',
                        'location': 'Spain',
                        'name': 'Adif',
                        'type': 'State-Owned Rail Infrastructure Manager'},
                       {'customers_affected': 'Patients (names, PESEL, '
                                              'addresses, contact details '
                                              'exposed)',
                        'industry': 'Healthcare/Software',
                        'location': 'Poland',
                        'name': 'Medyc (Qbusoft)',
                        'type': 'Medical Records Platform'},
                       {'location': 'Australia',
                        'name': 'Unnamed Australian Firms',
                        'type': 'Corporate'}],
 'attack_vector': ['Compromised Third-Party Servers',
                   'Stolen API Keys/Session Tokens',
                   'SQL Injection',
                   'Phishing (Malicious Downloads)',
                   'Legitimate Remote Management Tools'],
 'customer_advisories': ['Renfe notified affected customers (September 25)'],
 'data_breach': {'personally_identifiable_information': ['Names',
                                                         'Email addresses',
                                                         'National ID numbers '
                                                         '(PESEL)',
                                                         'Addresses',
                                                         'Contact details'],
                 'sensitivity_of_data': ['High (PESEL numbers, medical '
                                         'records)'],
                 'type_of_data_compromised': ['Customer names and email '
                                              'addresses',
                                              'Patient personal data (PESEL, '
                                              'addresses, contact details)']},
 'date_publicly_disclosed': '2024-09-25',
 'description': 'This week’s cybersecurity incidents highlight two key trends: '
                'artificial intelligence (AI) as both a target and an attack '
                'vector, and threat actors abusing trusted software to evade '
                'detection.',
 'impact': {'brand_reputation_impact': ['Renfe', 'Medyc/Qbusoft'],
            'data_compromised': ['Customer names and email addresses (Renfe)',
                                 'Patient names, national ID numbers (PESEL), '
                                 'addresses, and contact details (Medyc)'],
            'financial_loss': '$600,000 per incident (Australia)',
            'identity_theft_risk': ['High (Poland: PESEL numbers exposed)'],
            'operational_impact': ['Undetected intrusion for over two weeks '
                                   '(Medyc)',
                                   'Abuse of legitimate IT tools for '
                                   'persistence'],
            'systems_affected': ['Renfe (via Adif servers)',
                                 'Medyc medical records platform',
                                 'Corporate AI services (API keys/session '
                                 'tokens)',
                                 'Remote management tools (MSP360, ConnectWise '
                                 'ScreenConnect)']},
 'initial_access_broker': {'backdoors_established': ['ConnectWise '
                                                     'ScreenConnect for '
                                                     'persistence'],
                           'entry_point': ['Compromised Adif servers (Renfe)',
                                           'Phishing (MSP360 disguised as '
                                           'Zoom/Adobe updates)'],
                           'high_value_targets': ['AI services (API '
                                                  'keys/session tokens)',
                                                  'Medical records (PESEL '
                                                  'numbers)']},
 'lessons_learned': ['AI credentials (API keys, session tokens) are high-value '
                     'targets for attackers.',
                     'Legitimate remote management tools can be abused for '
                     'persistence and lateral movement.',
                     'Third-party supply chain vulnerabilities can expose '
                     'customer data even if primary systems are secure.',
                     'SQL injection flaws in medical platforms pose severe '
                     'risks to patient privacy.',
                     'AI is being used to scale cybercrime, including fraud '
                     'and deepfake-based attacks.'],
 'motivation': ['Financial Gain',
                'Data Theft',
                'Lateral Movement',
                'Fraud',
                'Cybercrime Scaling'],
 'post_incident_analysis': {'root_causes': ['Unpatched SQL injection '
                                            'vulnerability in Medyc platform',
                                            'Compromised third-party servers '
                                            '(Adif) with access to Renfe data',
                                            'Lack of multi-factor '
                                            'authentication (MFA) for AI '
                                            'credentials',
                                            'Abuse of legitimate remote '
                                            'management tools for malicious '
                                            'purposes']},
 'recommendations': ['Enforce strict access controls and monitoring for AI '
                     'credentials (API keys, session tokens).',
                     'Audit and secure third-party vendor infrastructure to '
                     'mitigate supply chain risks.',
                     'Patch and harden medical/enterprise software against SQL '
                     'injection and other common vulnerabilities.',
                     'Educate employees on phishing risks, especially '
                     'disguised as legitimate software updates.',
                     'Implement behavioral analytics to detect abuse of '
                     'trusted IT tools (e.g., remote management software).',
                     'Collaborate with law enforcement to address AI-driven '
                     'cybercrime threats.'],
 'references': [{'source': 'Renfe Public Disclosure'},
                {'source': 'Australian Signals Directorate (ASD) Warning'},
                {'source': 'Europol Cybercrime Conference (September 28–30)'},
                {'source': 'Microsoft Phishing Campaign Tracking'}],
 'response': {'communication_strategy': ['Public disclosure by Renfe '
                                         '(September 25)']},
 'title': 'Weekly Cybersecurity Roundup: AI as Target and Tool, Trusted '
          'Software Exploited in Attacks',
 'type': ['Data Breach',
          'Credential Theft',
          'Phishing',
          'Supply Chain Attack',
          'AI Exploitation'],
 'vulnerability_exploited': ['SQL Injection (Medyc Platform)',
                             'Third-Party Supply Chain Vulnerability (Adif '
                             'Servers)',
                             'Lack of AI Credential Protection']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.