Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Hacker Claims Sale of 20 Million Endesa Customer Records on Dark Net Forum

Hacker Claims Sale of 20 Million Endesa Customer Records on Dark Net Forum

By:
Last updated:July 20, 2026
Human Written
  • Someone’s claiming to have a huge Endesa customer database for sale, over 20 million people’s data, supposedly.

  • The alleged data is allegedly stored in a single SQL file of about 1.06TB. However, neither independent verification nor Endesa has confirmed the authenticity.

  • This follows a recent incident, where Endesa admitted that attackers got into their systems and leaked customer information, like contract details and a few IBAN numbers.

Hacker Claims Sale of 20 Million Endesa Customer Records on Dark Web Forum

A hacker going by the name ‘max987’ is advertising what they say is a stolen database supposedly covering info on over 20 million people in an underground forum.

According to the listing, the data is inside a single SQL database of about 1.06 terabytes in size. It allegedly includes fresh IBAN banking information from 2026.

They even included a sample archive, a file-tree preview, and 10,000 sample records to try to prove they’re legit. Currently, there’s no evidence confirming that the alleged data is actually from Endesa.

While the latest dark web sale remains unverified, it follows a confirmed cyberattack on Endesa earlier this year. A threat actor using the aliases “glock” and “spain” posted a database they claimed belonged to Endesa in early January.

According to the advert, the file contained a total of 1.05TB of data on over 20 million Endesa customers. Endesa later confirmed the breach, acknowledging that customer data had appeared on the dark web. The actor shared a sample archive and 10,000 sample records to back their claims.

In addition, the threat actor left a message that reads: “I hacked into Spain’s largest electricity and gas company (Endesa), access to everything, no one has this database except me.” They threatened to post more data if Endesa refuses to contact them.

Shortly after the listing, Endesa released a statement on January 11 disclosing a cyberattack. The Spanish energy company reported that the attack exposed sensitive data, which included customers’ bank account numbers and ID numbers.

According to Endesa, they found out that someone broke into their commercial platform. Investigations suggest the attacker got hold of customer ID details, contact info and national identity numbers.

Also, they stole energy contract data, and in some cases, International Bank Account Numbers (IBANs). However, the company assured its customers that the incident didn’t compromise their account passwords. They informed the relevant Spanish authorities in compliance with GDPR regulations.

Meanwhile, Outpost24’s threat intelligence team looked into the hacker’s claims. They think the data probably came from a Salesforce CRM platform. Looking at the file names and object types, it appeared the attacker extracted backend data using stolen employee credentials with special API access.

Is the Latest Listing the Same as the Old One?

Further analysis found that the first actor’s BreachForums account was new. They created the profile on January 3, with no other activity besides the Endesa posts.

Experts also described them as a Spanish-speaking threat actor with a limited presence in cybercrime forums. There was no evidence proving the attacker succeeded in selling any data. As of January 12, they were still promoting the database, suggesting their monetization efforts failed due to a lack of solid reputation.

Therefore, the latest advert raises eyebrows as to whether it’s the same actor using a different name to advertise the same database. Both listings share some similarities.

They claimed data on 20 million Endesa customers and offered 10,000 sample records and a sample archive. Also, the data size is similar. The latest posts mentioned 1.06TB while the previous listing claimed 1.05TB.

For now, all we have are assumptions, since the latest database hasn’t undergone any independent verification. Hackers love to recycle data from past breaches. They package it up and sell it as if it’s brand new. Sometimes they bloat the data size or inflate its value to draw in buyers or pressure companies into paying up.

Why this Breach is Dangerous

Criminals can’t use IBAN codes alone to empty a bank account. But they can become a powertools if hackers pair them with personal information, such as the name, address, phone number, and national identification details.

Cybersecurity professionals explain that with these credentials, hackers may create a very personalized phishing scam. The data includes unique supply point identifiers, which fraudsters can use to craft messages about a particular energy contract.

The customer may receive a message by SMS, WhatsApp, or via e-mail that looks like it’s from Endesa. Scammers may even try to charge the customers’ bank accounts directly or apply for instant credit.

According to Abel Gomez, CEO of Cibersegura security firm, the degree of personalization is so high that you fall for it.

How to Remain Secure

Beware of people who contact you via phone call, message or email saying that they work for Endesa. In case you receive any message from someone, verify its authenticity through Endesa. And don’t click on any links or open attachments if something feels off.

Also, monitor your bank account always; review statements every once in a while so you can spot unusual activity early. Remember, these attacks won’t stop anytime soon, your best bet at staying safe is to stay informed and cautious.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.