Spanish energy giant Endesa and provider Energía XXI have disclosed a serious cybersecurity incident, informing customers that unauthorized users gained access to company systems and data linked to energy contracts. The incident raises concerns about the protection of personal information in a critical infrastructure sector such as energy.

Who is Endesa and why is the incident significant?
Endesa is the largest electricity company in Spain and is now part of the Italian group Enel. It supplies electricity and natural gas to more than 10 million customers in Spain and Portugal, and serves around 22 million customers. Energía XXI operates as a provider within the same group, which explains why the incident affects multiple brands.
See also: BreachForums: Data leak exposes 324,000 criminals
The company's scale makes any data breach particularly critical, as even limited access can affect a huge number of citizens.
What we know about the breach
According to the official announcement, Endesa detected unauthorized access to its commercial platform, despite the security measures it implements. The company admitted that personal data of customers related to energy contracts was affected.
The investigation so far shows that the attackers gained access to basic identification details, contact information, national identity numbers (DNI), contract details, as well as payment data such as IBAN numbers. The companies clarified, however, that no passwords account.

The company's immediate measures
In response to the incident, Endesa blocked internal accounts that were considered compromised and collected logs for in-depth analysis. At the same time, increased monitoring mechanisms, aiming to identify possible suspicious activity on the network.
See also: HawkSec: Discord data is for sale
The company has already informed the Spanish Data Protection Agency and the competent national authorities, as required by the European GDPR framework, while the gradual notification of all affected customers is underway.
Is there a risk to consumers?
Endesa notes that, so far, there are no indications of fraudulent use of data, assessing that the risk of a serious impact on customers' rights and freedoms is low. Nevertheless, recipients of the notifications are urged to be vigilant.
The companies are warning of possible impersonation, identity theft and phishing, asking customers to immediately report any suspicious communication via a special support number.
Rumors of database sale on the dark web
At the same time, threat actors are claiming to for data from Endesa. The alleged data includes around 20 million records and almost 1 TB of SQL databases, which are being offered to an exclusive buyer. The samples, which have allegedly been published, appear to be consistent with the type of data reported by the company.

Endesa and Energía XXI limited themselves to the official announcement, without confirming or denying the authenticity of the specific allegations.
See also: Hacking group Everest says it breached Nissan
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Another bell for the cybersecurity of critical infrastructure
Although Energía XXI's services continue to operate normally, the incident once again highlights the importance of cybersecurity in critical sectors such as energy. Attacks are no longer only targeting technology companies, but also organizations with huge citizen databases.
The final picture will become clearer after the investigation is completed. Until then, the Endesa incident serves as a reminder that digital security is now a key pillar of reliability for any modern service provider.
Source: www.bleepingcomputer.com
