logo

New attack analysis: What you need to know about the Endesa data breach

ID: dc7a54be-0353-5806-8c29-f987adab6f7d

STIX ID: report--dc7a54be-0353-5806-8c29-f987adab6f7d

Feed Name: Outpost24 Blog

Threat Score
85/100

Date Published: 2026-01-15

Date Updated: 2026-04-28

Author: dimber

...
...

Outpost24 analyzed an alleged January 2026 Endesa breach in which a threat actor offering aliases “glock”/“spain” advertised a Salesforce-origin dataset of over 20 million customers containing identity, contractual and payment details; the report attributes likely initial access to compromised legitimate credentials enabling backend/API exports, documents the actor's forum and Telegram activity, assesses dataset filenames/structure as consistent with CRM/Data Cloud exports, and recommends continuous credential exposure monitoring, token revocation, and tighter IAM controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.