Endesa (Enel Group) disclosed unauthorized access to its Energía XXI commercial platform, resulting in exposure of customer contract-related personal and financial data. Impacted data types reported include identification and contact details, Spanish national identity numbers (DNI), contract information, and payment details including IBANs; Endesa stated that account passwords were not exposed and that there was no evidence of fraudulent use at the time of notification.
Endesa reported taking containment and investigation steps including blocking access to compromised internal accounts, collecting and analyzing logs, and increasing monitoring for suspicious activity while notifying affected customers. The incident was reported to Spanish authorities including the Spanish Data Protection Agency (AEPD) and referenced coordination with national cybersecurity bodies; reporting also noted an attacker claim of large-scale SQL data theft and attempted sale on a dark web forum, though Endesa’s public statements emphasized the breach was limited to customer data access and did not involve operational disruption or ransomware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By January 15, 2026, Outpost24 published analysis assessing that the intrusion most likely involved compromised legitimate credentials rather than ransomware or operational disruption. The firm also assessed the exposed data source was consistent with Salesforce CRM and related data cloud layers accessed through elevated API or integration privileges.
After confirming the breach, Endesa blocked compromised internal accounts, began log analysis, increased monitoring, and notified affected customers. The company also reported the incident to Spain's Data Protection Agency and other relevant authorities, while stating operations were not affected and no fraudulent misuse had been confirmed.
On January 11, 2026, Endesa confirmed a security incident involving unauthorized access to its commercial platform. The company said exposed data may include customer identification and contact details, DNI numbers, contract information, and IBANs, while passwords were not compromised.
On January 4, 2026, the seller posted sample data to support claims that Endesa customer records had been stolen. Multiple reports said the samples were presented alongside offers to sell the alleged database on dark web forums.
In early January 2026, a threat actor using the aliases "glock" and "spain" began advertising an allegedly stolen Endesa database on cybercrime forums. The actor claimed the data included personal and financial information for more than 20 million people and over 1 TB of SQL database data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
outpost24.com
Open sourcescworld.com
Open sourcerescana.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.