Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Endesa

Endesa Vendor Cyber Rating & Cyber Score

endesa.com

We are leaders in the Spanish electric power industry and the second operator in the Portuguese electric market. With more than 10 thousand employees, we provide our services to 12.6 million clients and our core business is the production, transportation, distribution and commercialization of electric power. We also operate in the natural gas sector and we develop other energy-related services. We are a company that looks ahead to the future: we bet on a more sustainable energetic culture and we are committed with our responsibility of actively contributing to the construction of an intelligent energetic future through innovation. From the third trimester of 2009, we are part of the Enel group, the biggest electric power company in Italy


Endesa A.I CyberSecurity Scoring

Endesa
Company Information
Website:http://www.endesa.com
Employees number:7,444
Number of followers:328,462
NAICS:22
Industry Type:Utilities
Homepage:endesa.com
Endesa Risk Score (AI oriented)
Between 700 and 749
logo
EndesaUtilities
Updated:
02/05/2026
713/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Endesa Global Score (TPRM)
xxxx
logo
EndesaUtilities
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Endesa
EndesaModerate
Current Score
713Ba (MODERATE)
01000
2 incidents
-52 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
715Before Incident
MAY 2026
713Before Incident
APRIL 2026
713Before Incident
MARCH 2026
710Before Incident
FEBRUARY 2026
707Before Incident
JANUARY 2026
761Before Incident
Breach
12 Jan 2026Endesa
Endesa: Spanish energy giant Endesa discloses data breach affecting customers

Unauthorized Access to Endesa and Energía XXI Customer Data

706After Incident
CRITICAL-55
END1768237930
Endesa and Energía XXI Report Data Breach Affecting Millions of Customers Spanish energy provider Endesa and its subsidiary Energía XXI have disclosed a data breach involving unauthorized access to customer contract information. The incident, detected on an unspecified date, exposed personal and financial details of affected clients, though no account passwords were compromised. Scope and Impact Endesa, Spain’s largest electric utility company under the Enel Group, serves over 22 million customers across Spain and Portugal. The breach targeted its commercial platform, with hackers accessing: - Basic identification details (names, addresses) - Contact information (phone numbers, emails) - National identity numbers (DNI) - Contract and payment details, including IBANs While the company states there is no current evidence of fraudulent data misuse, it acknowledges potential risks, including identity theft and phishing attacks. Endesa has notified Spain’s Data Protection Agency and relevant authorities, implementing heightened monitoring and blocking compromised internal accounts. Ongoing Investigation and Threat Actor Claims The breach’s full extent remains under investigation, with Endesa pledging to notify affected customers as new details emerge. Meanwhile, threat actors have advertised a purported 1TB database of Endesa customer records allegedly 20 million entries for sale to a single buyer. The samples align with the data types Endesa confirmed were accessed, though the company has not verified the hackers’ claims. Energía XXI has assured customers that operations and services remain unaffected, with no disruption to energy distribution. The company continues to analyze logs and reinforce security measures.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain (Data for Sale)
IMPACT
Data Compromised: Basic identification details, contact information, national identity numbers (DNI), contract details, payment details (IBANs)Systems Affected: Commercial platformOperational Impact: No impact on operations or servicesIdentity Theft Risk: High (identity impersonation, phishing attacks)Payment Information Risk: High (IBANs exposed)
DATA BREACH
Basic identification detailsContact informationNational identity numbers (DNI)Contract detailsPayment details (IBANs)Number Of Records Exposed: 20 million (alleged)Sensitivity Of Data: High (PII, financial data)File Types Exposed: SQL databases
JANUARY 2026
808Before Incident
Breach
01 Jan 2026Endesa
Endesa and Naturgy: Naturgy: 74.2 GB of data on the dark web affect 3% of its portfolio, close to 480,000 records

Naturgy Data Breach Exposes Personal and Financial Information of Nearly Half a Million Spanish Customers

759After Incident
CRITICAL-49
ENDNAT1777732165
Naturgy Data Breach Exposes Personal and Financial Information of Nearly Half a Million Spanish Customers A significant data breach has compromised the personal and financial details of Naturgy clients in Spain, with cybercriminals offering 74.2 GB of stolen data allegedly belonging to over 1.8 million users on the dark web. The energy distributor confirmed that approximately 480,000 records were affected, representing around 3% of its commercial portfolio. The exposed data includes full names, national identification numbers (DNI/NIF), email addresses, bank account details, and contractual information such as CUPS codes, physical addresses, and internal provider notes. Naturgy clarified that the breach did not originate from its own systems but from a third-party database storing sensitive customer information. In response, the company activated incident protocols, renewing credentials, blocking unauthorized access, and conducting audits on both its platforms and the affected provider’s servers. While passwords and access to the client portal remained secure, Naturgy has notified impacted individuals and filed reports with the Spanish Data Protection Agency and law enforcement. This incident follows a similar attack earlier this year, where the same threat actor targeted Endesa, compromising data from 20 million subscribers and later leaking 300,000 files in an apparent ransom attempt. Authorities continue investigating the attacks to trace their origin and strengthen protections for sensitive data. Affected Naturgy customers have been advised on verifying corporate communications to mitigate risks of identity theft.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data exfiltration for potential ransom or sale on dark web
IMPACT
Data Compromised: Personal and financial information (full names, national IDs, email addresses, bank account details, contractual information)Systems Affected: Third-party database storing customer informationBrand Reputation Impact: Potential reputational damage due to exposure of sensitive customer dataLegal Liabilities: Potential regulatory fines and legal actionsIdentity Theft Risk: High risk of identity theft for affected customersPayment Information Risk: High risk of payment fraud due to exposed bank account details
DATA BREACH
Personal informationFinancial informationContractual informationNumber Of Records Exposed: 480,000 (confirmed), 1.8 million (alleged)Sensitivity Of Data: High (national IDs, bank account details, email addresses, physical addresses)Data Exfiltration: Yes (74.2 GB of data offered on dark web)Personally Identifiable Information: Full names, national identification numbers (DNI/NIF), email addresses, physical addresses
DECEMBER 2025
808Before Incident
NOVEMBER 2025
808Before Incident
OCTOBER 2025
808Before Incident
SEPTEMBER 2025
808Before Incident
AUGUST 2025
808Before Incident
JULY 2025
808Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Endesa ?
?
What was Endesa's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Endesa's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Endesa's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Endesa's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Endesa's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Endesa's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Endesa's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Endesa's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Endesa's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Endesa's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Endesa's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Endesa's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Endesa ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Endesa's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?