Renfe and Adif: 500 Gigabytes That Don't Match Names and Emails
How much does a name and email address weigh? Renfe says that's exactly what attackers took from their servers. And that's where the problem begins: 500 gigabytes, the figure attributed by El Mundo, doesn't add up with a list of emails. Not even close. According to the railway company's statement reported by EFE, the incident originated on the servers of Adif, the infrastructure manager, which had already been attacked previously. The stolen information was reportedly 'limited': names and emails. Nothing more. And, above all, with no impact on service provision, the company insists.
The Calculation of the 500 Gigabytes That Doesn't Work
If what was stolen is one name and one email per customer, the arithmetic has to work. And it doesn't. An email and a name take up, at most, a few kilobytes. To reach 500 gigabytes, you'd need to multiply by orders of magnitude what the company itself admits. One user put it in writing: 100 million words in plain text occupy between 550 and 650 megabytes, a little over half a gigabyte. In other words, to justify 500 gigabytes, one would have had to steal the equivalent of an entire library, not a contact list.
This is where a forum user's comment, summarizing the confusion, comes from: 'they stole a book from each client and we didn't even know we had it written down.' The scale doesn't match the narrative. The figure might be inflated, it might refer to database dumps with a lot of internal noise, or perhaps no one has explained what that package truly contains.
Who Provides an Email and Who Only Gives a Mobile Number
There's a detail that, according to some forum users, narrows down the possibilities: for medium-distance routes, Renfe doesn't always ask for an email; in many cases, a mobile number is sufficient. Those who buy tickets at the counter may never have provided their email. The linked emails would primarily be from those who buy tickets online, according to the forum. A smaller universe than the 500-gigabyte figure suggests.
The other aspect of the issue, according to a forum user, is who oversees all this. They claim, without providing proof, that cybersecurity for a large part of the public sector is outsourced, and that major providers accumulate incidents in public administrations without anyone taking action. The model is pointed to, not a specific name. The pattern repeats, in their opinion: the shield is outsourced, and when the attacker gets in, the explanation is also outsourced.
The company maintains that there is no evidence of access to more data and that the service has not been affected. With this information, citizens can only wait for someone to clarify, someday, how 500 gigabytes fit into a name and an email. If they do fit.
Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication.
Read the full discussion (28 replies).
Ministry officials under suspicion request transfers to avoid signing illegal documents. Political pressure and fear of reprisals trigger a mass exodus...
The Diada in Catalonia is characterized by deep division between celebration and political friction, accompanied by falling attendance figures and an uncertain economic impact.