Endesa Says Full Customer Data Exposed in Breach
Endesa says a cyberattack exposed sensitive customer data after an unauthorized party accessed its commercial platform. The Spanish electricity giant reported that attackers may have obtained identification details, contract data, national ID numbers, and possibly bank account numbers, but no passwords. Endesa, which serves over 10 million customers and reported €21.3 billion in revenue in 2024, confirmed it isolated the incident and activated its security protocols. It has alerted regulators and affected users.
A threat actor claimed responsibility on a cybercrime forum, asserting theft of 1.05 terabytes of data affecting more than 20 million individuals. The attacker said the database contained exclusive, previously unseen information. Endesa is working with suppliers to investigate and continues monitoring its systems. While the firm sees no signs of fraud so far, it warns of risks like impersonation and phishing attempts.
Endesa says all services remain operational. Customers should stay alert and report suspicious activity.
Threat actor claims the theft of full customer data from Spanish energy firm Endesa
