Published 4 months ago • loading... • Updated 4 months ago
Endesa Probes Breach After Hackers Claim Huge Data Haul
Attackers accessed about 1TB of customer contract and payment data from Endesa’s commercial platform, with samples of 20 million records allegedly published for sale.
Endesa and its Energía XXI operator disclosed unauthorized access to their commercial platform and are notifying affected customers, promising direct alerts in the coming days.
Last week, threat actors published alleged samples of stolen Endesa data and claim about 20,000,000 records, offering the dataset to a single exclusive buyer with around 1TB in SQL databases, BleepingComputer reported.
Investigators say the intruders accessed identification, contact info, DNI, contract and payment details including IBANs, while Energía XXI and Endesa confirmed account passwords were not exposed.
Endesa blocked access to compromised internal accounts, dumped log records for analysis, established elevated monitoring, notified the Spanish Data Protection Agency, and urged letter recipients to report suspicious activity.
With about 22,000,000 clients, the incident affects Endesa, Spain's largest electric utility owned by Enel Group; BleepingComputer contacted Energía XXI and Endesa but further details remain pending.
The Endesa, one of the largest energy companies in Spain and belonging to the Italian Enel group, has recently confirmed being subjected to a cyberattack that resulted in unauthorized access to customer data....