It took a hacker two and a half hours to steal thousands of personal data from Endesa customers. Endesa took a week to notify

Endesa Energy has confirmed a cyberattack on its trading platform that has exposed critical information of millions of customers. The breach includes identity documents, bank accounts and data from electricity and gas contracts, which places those affected at risk of fraud and identity theft. What exactly happened. A cybercriminal has managed to circumvent the security measures of Endesa’s commercial platform and access sensitive customer information related to their energy contracts. According to has recognized the company in communications sent to those affected, during the security breach contact information, ID and IBAN numbers from bank accounts would have been extracted. The company ensures that the access passwords have not been compromised. The magnitude of the incident. The hacker responsible, who identifies himself as “Spain,” posted on January 4 on BreachForums, a popular forum in the dark webdetails of the attack claiming to have obtained more than 1 TB of information corresponding to more than 20 million people, according to reported the Digital Shield medium. The cybercriminal assured this medium that he had gained access in less than two and a half hours, and has gone so far as to leak data samples from a thousand clients to demonstrate the authenticity of the stolen information. What type of data is at stake. The hacker claims to have obtained basic personal data (names, surnames, postal addresses and contact information), financial information (IBAN, billing data and account history), energy data (CUPS, active electricity and gas contracts, supply point information) and regulatory data. The risks for clients. Although Endesa considers it “unlikely” that the theft will result in “a high-risk impact on the rights and freedoms of users,” the company warns of several real dangers in its official statement. Cybercriminals could try to impersonate customers, post the data on digital forums, or use it for phishing and spam campaigns. Josep Albors, Director of Research and Awareness at ESET Spain, explains that “the risk does not end with the notification of the breach” and that the exposed information can be reused for months or years to launch targeted fraud. Endesa’s response. The energy company has taken almost a week to publicly acknowledge the incident since the leak became known. The company claims to have immediately activated security protocols, blocked compromised access and notified the competent authorities of the case. In addition, it has enabled telephone lines to resolve doubts: 800 760 366 for Endesa Energía customers and 800 760 250 for those of Energía XXI, its distributor in the regulated market. We have contacted the company to find out more information about it, so we will update the article in case of news. What should those affected do? The problem with this security breach is that the data is surely used for advertising campaigns. phishing and targeted spam. As explained by ESET, the first thing we should keep in mind as affected parties is to distrust any communication that appears to come from Endesa and that includes links, attachments or urgent requests, always contacting the company through official channels. This has not been the case, but it never hurts to frequently review bank accounts to detect unauthorized movements and change passwords, even if the company claims that they have not been compromised, activating security protocols whenever possible. two factor authentication. Free and useful websites like ‘Have I Been Pwned‘ allow us to check if the data has appeared in other known breaches by entering our email. The extortion attempt. According to account According to Escudo Digital, the hacker has tried to negotiate directly with Endesa through emails, although at the moment he has not set a specific ransom figure. The cybercriminal, who says he is not affiliated with any group of ransomware known, has received offers from third parties of up to $250,000 for half of the database, although he claims to have not sold anything yet. “I prefer to wait for Endesa to decide,” he told the media. A worrying trend. Just like they count From the media Expansión, this attack places Endesa on the growing list of large Ibex 35 companies that have suffered cyberattacks in recent months. Companies such as Iberdrola, Iberia, Repsol and Banco Santander have been victims of similar incidents that have compromised customer data. And they have not been the only ones, since cyberattacks and data leaks They are now much more common. In the case of Endesa it seems that we will have to wait for the company to offer more information on the matter. Cover image | Endesa In Xataka | OpenAI just assumed an uncomfortable truth about AI browsers: there is one type of attack that is impossible to block

There are so many people growing marijuana in their homes that Endesa has a problem. And it will solve it with ia

In the industrial areas of many towns or cities, the constant buzzing of high pressure lamps illuminates hundreds of marijuana plants that grow to the rhythm of stolen electricity. It is a scenario that is repeated daily throughout Spain, where illegal cannabis cultivation and electric fraud They have woven a network of silent crime. Faced with this threat, Endesa has taken another step. Root cut. Endesa and the General Police Station of the National Police have signed a collaboration protocol to strengthen the fight against crimes that affect the electricity supply. From the massive electricity fraud to the theft of material, sabotages and even cyberators, as collects the press release. A more joint action. The protocol foresees, among other measures, joint training, information exchange, analytical reports, technical field advice. In addition, it contemplates the active participation of the Judicial Police in technical actions of Endesa and addresses associated crimes such as the manipulation of measuring equipment, the theft of personal data or scams to consumers by cybercriminals. A problem that does not stop growing. According to the European drug report 2025, Spain concentrate 73% Of all the seizures of marijuana in the EU, many of them in plantations Indoor connected fraudulently to the network. Only in the last year, the Endesa networks subsidiary, e-distribution, disconnected 2,214 illegal hooks related to crops, with a consumption equivalent to 70,000 homes. The data is replicated in different areas of the country. In Granada, like has detailed ABC Granada, between January and April of this year, Endesa has detected 246 illegal plantations, at the rate of two a day. In Córdoba, in the same period, 19 files have been opened, which is equivalent to one per week, According to the Córdoba Diario. In both cases, the excessive consumption – quoted to the up to 80 homes by plantation – saturates the network and causes collateral damage. The highest invoice. The impact goes far beyond the economic. These illegal connections cause constant overloads, with serious safety consequences. Last summer, 24 fires were recorded in the distribution network in Andalusia, five of them in Granada and four in Córdoba, directly linked to marijuana plantations, According to the Córdoba Diario. Technology at the service of prevention. To deal with this challenge, Endesa has opted for prevention. For years, predictive models based on artificial intelligence and Big Data have applied to detect suspicious patterns. Now, it has also begun to display smart sensors in its networks, capable of anticipating overloads before they occur. A battle without rest. Electric fraud linked to illegal marijuana culture not only challenges electricity, but also the coexistence model in many areas of the country. The answer is already underway, but the challenge – technical, police and social – has just begun. Image | Pexels Xataka | There are so many marijuana crops in Spain that they are causing problems to one of their great industries: electricity

Log In

Forgot password?

Forgot password?

Enter your account data and we will send you a link to reset your password.

Your password reset link appears to be invalid or expired.

Log in

Privacy Policy

Add to Collection

No Collections

Here you'll find all collections you've created before.