Security Guides
The call that already knows your contract is the scam: what to do after the Endesa data breach (DNI and IBAN)
Spain's Endesa Energía disclosed in January 2026 unauthorized access to its commercial platform, with ID (DNI), contact, contract data and possibly IBANs taken. What to do about fake calls, direct debits and ID misuse.
For: current and former Endesa customers in Spain who received the incident notice, and anyone getting calls "from the electricity company" from someone who knows their ID number. This article is based on Endesa Energía's official notice and guidance from INCIBE (Spain's national cybersecurity institute), the AEPD (the Spanish Data Protection Agency), the Bank of Spain and the National Police. It does not cover how the attack was carried out.
What customers should do today
Read the notice and ask which of your data was affected
Endesa says it notified every customer whose data was compromised. If you are unsure about your case, write to Endesa Energía's Data Protection Officer (contactodpo@endesa.es). According to the AEPD, the right of access is free and the company must reply within one month (extendable by two more in complex cases). To report anything suspicious, Endesa gives the phone number 800 760 366. Contact those channels yourself; don't reply to a message that arrives "on behalf of Endesa".
If someone calls 'from Endesa', hang up and call the official number yourself
INCIBE puts it simply: when in doubt, hang up and call them yourself on the official number. Endesa's website has a lookup, "Comprueba quién te ha llamado" (check who called you), that tells you whether a number is authorized by Endesa Energía. But INCIBE warns that the number shown on your screen can be faked (phone spoofing), so a "correct" number isn't enough: the safe check is to hang up and dial yourself.
Never give out SMS codes or bank details, or 'confirm' your data
Endesa says it will never ask you to verify your details on an unsolicited call; it only asks for information when you are signing or changing a contract. A caller who announces "a security code by SMS" to "verify your contract" is one of the warning signs Endesa describes in its guide to fraudulent calls. Don't tap links in texts about debts, cut-offs or penalties either (see what is phishing?).
Check the direct debits on your account
Look through your statements for direct debits (recibos domiciliados) from creditors you don't recognize. According to the Bank of Spain, Royal Decree-law 19/2018 gives you the right to have them refunded: if you did not authorize the debit, you have 13 months; if you did, 8 weeks under the conditions the law sets. Ask your bank for the refund and state the reason.
If you suspect a loan in your name, check CIRBE
The Bank of Spain advises checking its Central Credit Register (CIRBE) if you suspect someone took out a loan, credit or guarantee in your name. Your own report is free, and the detailed version shows which institution granted each operation.
If fraud happens: police report, your bank, and the AEPD
File a report (denuncia) at a National Police station or a Civil Guard post. The National Police lets you start it through its online reporting office (Oficina Virtual de Denuncias) and then sign it at a station (within 72 hours). Tell your bank and the company where the transaction was made. For data protection matters, the competent authority is the AEPD. For advice, INCIBE's 017 helpline is free and confidential (also on WhatsApp at 900 116 117), 8 a.m. to 11 p.m., every day.
Passwords didn't leak, but don't reuse them
Endesa says passwords were not compromised. Even so, INCIBE recommends strong passwords that are different for every service. If you used the same one elsewhere, change it there. A password manager makes that easy.
DNI + contact + contract
→ A "tariff change", "supply cut-off" or "debt" call or text that already knows who you are
Check: hang up and call the official number yourself
IBAN
→ Direct debits you never authorized
Check: debits on your statement (refund up to 13 months)
DNI + IBAN together
→ Attempts to sign contracts in your name
Check: CIRBE report; if fraud, file a police report
Passwords were not compromised (per Endesa)
What happened (per Endesa and Spanish authorities)
The following comes from Endesa Energía's notice to customers and INCIBE's alert. Endesa has not published the detection date or the number of people affected.
January 12, 2026
Endesa Energía notifies customers of the incident and posts the notice on its website (date per BleepingComputer). It says it detected unauthorized and illegitimate access to its commercial platform.January 13
INCIBE publishes the alert "Endesa notifies its customers of a personal data leak" with high importance. It says the data relates to contracts with Endesa's free-market and regulated-market retailers.After initial assessment
Endesa reports the incident to the competent authorities, including the Spanish Data Protection Agency (AEPD). Its investigation, internally and with its suppliers, is ongoing.March 31
Endesa updates its guide to fraudulent calls and texts with real 2026 examples (alleged debts, "supply cut-off within 12 hours"). In that guide, Endesa states that these fraudulent calls are not related to Endesa Energía or to its processing of personal data.
- Possibly exfiltrated
- Basic identification data, contact details, DNI, data about the contract with Endesa Energía and, in some cases, payment details (IBAN)
- Not affected
- Password access data ("in no case", per Endesa)
- Fraudulent use
- As of the notice, Endesa says there is no evidence of fraudulent use of the data
- Endesa's measures
- Immediate blocking of the compromised access accounts, log analysis, notification of affected customers and special ongoing monitoring of its systems
- Authorities
- Reported to the competent authorities, including the AEPD
- Service
- Operations and services are running normally, according to the company
- Official contact
- Customer line 800 760 366 · Data Protection Officer: contactodpo@endesa.es
How to read it: 'no evidence of fraudulent use' does not mean 'no risk'
Endesa's own notice lists the risks: someone may try to impersonate you or usurp your identity, publish the data, or use it for phishing or spam. That's why it asks customers to watch for suspicious messages and not to give personal data to people they don't know first-hand. The risk doesn't expire in a few weeks: an ID number and an IBAN don't expire the way a password can be reset.
The same old energy scam, and why this data makes it more convincing
Calls from fake "energy advisers" didn't start with this breach. Endesa's guide describes the usual scripts: "electricity prices are going up, you should switch supplier", "this change means a change of billing company", "we're calling to verify your contract details; you'll get an SMS with a code", or the threat of a supply cut-off or penalty with a deadline. The same guide warns that scammers often have personal data such as your DNI, phone number or address and use it to win your trust.
Signs of a fake call
- "We're calling from a retailer linked to Endesa" or "partnered with your electricity company"
- Recites your DNI or address to sound legitimate
- Pressure: price rise, cut-off within hours, penalty
- Asks for an SMS code or your bank details
- Claims to be the distribution company switching your retailer
What Endesa says it does
- Always identifies itself as Endesa Energía
- Doesn't ask you to verify data on unsolicited calls
- Only asks for data when you're signing or changing a contract
- Distribution companies never call to switch your retailer
- If in doubt: hang up and call the official channels yourself
The lesson isn't "learn to spot scammers"; it's changing the rule you use to trust a caller. Before, someone knowing your DNI and contract was a reasonable sign they were your supplier. After a breach like this, that sign is worthless: never verify a call using the call itself. The same goes for the number on screen: INCIBE explains it can be faked, including to imitate electricity companies.
The IBAN: where to look and how long you have
An IBAN can't be used to log in to your online banking, but it can appear on a direct debit you never signed. The defense is dull and effective: look at your debits.
This site's view: your bank statement is the alarm you already have
You don't need to pay for a monitoring service. Every SEPA direct debit on your statement shows the name of the creditor collecting it. Once a month, scan the last few months of debits and flag any you don't recognize. Because you have 13 months to reverse an unauthorized debit, a monthly check leaves plenty of margin. If your bank's app can notify you of every charge, turn it on: it's the fastest way to see one.
For companies that store ID numbers and IBANs, the lesson is different: this data can't be "reset" like a password, so limit who can look it up, and how many records at once. We cover that in the minimum security baseline for organizations, and the legal frame in what is the GDPR?.
The closest parallel this year is the Odido breach in the Netherlands, where IBANs and ID numbers also leaked and Dutch authorities gave very similar advice: don't rush to replace documents, check your direct debits, and doubt anyone who "knows" your numbers. For a case where a genuine compensation program made fake messages more convincing, see the TVING breach in South Korea.
Sources (public record)
The facts in this article are based on the public sources below. Attacker claims and unpublished figures are not used.
- Endesa Energía, customer notice on the security incident (Spanish) — endesa.com
- INCIBE, "Endesa notifica a sus clientes una filtración de datos personales" (January 13, 2026, Spanish) — incibe.es
- INCIBE, Tu Ayuda en Ciberseguridad (017 helpline, Spanish) — incibe.es / "Spoofing telefónico: cuando la llamada parece legítima" — incibe.es
- Endesa, "Llamadas fraudulentas: cómo detectarlas y cómo actuar" (updated March 31, 2026, Spanish) — endesa.com / "Comprueba quién te ha llamado" — endesa.com
- AEPD, "Ejerce tus derechos" (Spanish) — aepd.es
- Bank of Spain (Banking Customer Portal), "Adeudos domiciliados" (Spanish) — clientebancario.bde.es / "Custodia tus datos: conoce los riesgos de la suplantación de identidad" — clientebancario.bde.es / CIRBE — clientebancario.bde.es
- National Police, Oficina Virtual de Denuncias (Spanish) — denuncias.policia.es
- BleepingComputer, "Spanish energy giant Endesa discloses data breach affecting customers" (January 12, 2026; used for the date only) — bleepingcomputer.com
Update history
2026-09-30: First version, based on Endesa Energía's notice (as checked on September 30, 2026; no affected count published), INCIBE's January 13, 2026 alert, and guidance from the AEPD, the Bank of Spain and the National Police.
Read next
- The closest parallel: The Odido data breach (IBANs and ID numbers leaked)
- Fake calls and messages: What is phishing? / Fake virus warnings (tech-support scams)
- Protecting your accounts: Choosing a password manager / Choosing multi-factor authentication
- Other 2026 incidents: The TVING data breach / List of breaches and cyberattacks (Japan and worldwide)
- For operators: The minimum security baseline for organizations
FAQ
QWhat data was leaked in the Endesa breach?
According to Endesa Energía's notice, the investigation indicates that the malicious actor may have accessed and exfiltrated basic identification data, contact details, DNI (Spanish national ID) numbers, data about the customer's contract with Endesa Energía and, in some cases, payment details (IBANs). Endesa says password access data was not compromised in any case.
QHow many customers were affected?
Endesa has not published the number of affected customers in its notice, and this site has not found a figure published by Endesa or the AEPD. Figures circulating online come from those claiming responsibility for the attack and are unconfirmed, so this article does not use them. Endesa says it notified every customer whose data was compromised.
QHow can I tell whether a call is really from Endesa?
Spain's national cybersecurity institute INCIBE advises that, when in doubt, you hang up and call the company yourself on its official number. Endesa says it always identifies itself as Endesa Energía, never asks you to verify your details on unsolicited calls, and that distribution companies never call to switch your retailer. Endesa offers an online lookup to check whether a number is authorized, but the number on your screen can be faked, so calling the official number yourself remains the safest check.
QMy IBAN leaked. Can someone charge direct debits to my account?
An IBAN cannot be used to log in to your online banking, but it can appear on direct debits you never authorized. Check the direct debits on your statements. According to the Bank of Spain (Royal Decree-law 19/2018), if you did not authorize a debit you have 13 months to have it refunded; if you did authorize it, the period is 8 weeks under the conditions the law sets.
QWhat should I do if someone uses my DNI?
The Bank of Spain advises checking its Central Credit Register (CIRBE) if you suspect a loan was taken out in your name, filing a report at a National Police station or Civil Guard post, and going to the AEPD for data protection complaints. The National Police lets you start a report through its online office; it must then be signed at a station within 72 hours.
QDo I need to change my Endesa password?
Endesa says passwords were not compromised. INCIBE still recommends strong, different passwords for each service. If you reused your Endesa password elsewhere, change it there. Be suspicious of any message asking you to change it through a link.