Threat actor claims the theft of full customer data from Spanish energy firm Endesa
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内,并且不需要特定的开头。首先,我得仔细阅读文章,理解主要信息。 文章讲的是西班牙能源公司Endesa遭遇数据泄露事件。黑客声称窃取了完整的客户数据,包括联系信息、身份证号码和支付信息。Endesa已经通知受影响的客户和当局,并采取了安全措施。虽然目前没有证据显示数据被滥用,但客户仍需警惕诈骗行为。 接下来,我需要将这些关键点浓缩成一句话。要确保包含公司名称、事件性质、泄露的数据类型以及公司的应对措施。同时,要保持语言简洁明了。 可能的结构是:西班牙能源公司Endesa遭遇数据泄露,黑客窃取了包括联系信息、身份证和支付数据在内的客户资料。公司已采取措施并通知客户和当局,目前未发现数据滥用迹象。 这样大约在100字以内,涵盖了所有重要信息。 </think> 西班牙能源公司Endesa遭遇数据泄露事件,黑客声称窃取了包括联系信息、身份证号码和支付数据在内的1.05TB客户资料。公司已激活安全协议并通知受影响客户及当局,目前未发现数据滥用迹象。 2026-1-13 19:34:16 Author: securityaffairs.com(查看原文) 阅读量:0 收藏

Threat actor claims the theft of full customer data from Spanish energy firm Endesa

Endesa disclosed a data breach exposing full customer data, including contact details, national ID numbers, and payment information.

Spanish energy firm Endesa disclosed a data breach, threat actors stole full customer data, including contact details, national ID numbers, and payment information.

“In this regard, we regret to inform you that Endesa Energía has detected a security incident that has allowed unauthorized and illegitimate access to its commercial platform. This incident has compromised the confidentiality of certain data for which Endesa Energía is responsible.” reads the statement published by the company. “Despite the security measures implemented by this company, we have detected evidence of unauthorized and illegitimate access to certain personal data of our customers related to their energy contracts, including yours. “

Endesa is a major Spanish multinational electric utility company and the largest electricity provider in Spain. It generates, distributes and sells electricity and natural gas, serving over 10 million customers domestically. Endesa is a majority-owned subsidiary of Italian utility group Enel, which holds about 70 % of its shares.

The company has around 8,900 employees (2024 figure). In 2024, Endesa reported €21.3 billion in revenue and a net profit of about €1.89 billion, reflecting strong earnings growth compared with the previous year.

Endesa Energía said attackers accessed and may have exfiltrated customer identification, contact details, national ID numbers, contract data, and possibly IBANs, but not passwords. The company activated security protocols and blocked access that had been compromised. Endesa notified affected customers and authorities, including Spain’s Data Protection Agency. Continuous monitoring is underway while investigations with suppliers continue.

The energy company says it has found no evidence that attackers have misused the affected data, so it considers a serious impact on customers unlikely. However, criminals could still try to impersonate customers, publish stolen data, or launch phishing or spam campaigns.

“As of the date of this communication, there is no evidence of any fraudulent use of the data affected by the incident, making it unlikely that a high-risk impact on your rights and freedoms will materialize. Even so, this unauthorized access to your data by the malicious actor could lead to an attempt to impersonate you, publish this data (resulting in a loss of control over it), or use it to carry out phishing or spam campaigns against you.” concludes the statement.

Customers should stay alert to suspicious calls, emails, or messages and report any concerns to the Endesa call center at 800.760.366. The company advises never sharing personal or sensitive information with unknown contacts and to notify Endesa or law enforcement if fraud is suspected. The Spanish firm confirms that all operations and services continue to run normally.

Endesa did not disclose technical details about the attack that caused the data breach; however, a threat actor claimed on a cybercrime forum to have stolen 1.05 terabytes of data from the company.

Below is the message published by the threat actor on the hacking forum:

“!I hacked into Spain’s largest electricity and gas company (Endesa), access to everything, no one has this database except me.

This thread was accepted and the data was verified as real and unique.

Price: negotiable Total size: (1,055,950,885,115 bytes)

More than +20.000.000 people in one single .sql (fresh data, never seen)!”

Endesa
Source X

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)




文章来源: https://securityaffairs.com/186861/cyber-crime/threat-actor-claims-the-theft-of-full-customer-data-from-spanish-energy-firm-endesa.html
如有侵权请联系:admin#unsafe.sh