
Dear customer,
For Endesa Energía S.A. ('Endesa Energía'), the protection of privacy and the security of the personal data we process is a priority commitment, as is transparency in communicating any relevant aspects in this regard.
We regret to inform you that Endesa Energía has detected a security incident which has allowed unauthorised and illegitimate access to its commercial platform. This incident has compromised the confidentiality of certain data for which Endesa Energía is responsible.
Despite the security measures implemented by this company, we have detected evidence of unauthorised and illegitimate access to certain personal data of our customers relating to their energy contracts, including yours. The investigation at the present time indicates that the malicious actor may have had access to, and could have exfiltrated from our systems, basic identifying data, contact details, ID numbers (DNIs), and data relating to your contract with Endesa Energía and potentially your payment details (IBANs); however, in no case have passwords been compromised.
As soon as Endesa Energía became aware of the incident, the security protocols and procedures established for this purpose were activated, as well as all necessary technical and organisational measures to contain it, mitigate its effects, and prevent its recurrence in the future, thereby allowing the detected incident to be contained immediately and satisfactorily and preventing further unauthorised access. These measures include, among others, the immediate blocking of compromised user accounts, the analysis of log records, and the notification of all customers whose data have been compromised. Equally, special continuous monitoring of the systems is being carried out to detect any suspicious activity. Furthermore, in compliance with applicable regulations, following an initial assessment of the incident, Endesa Energía has notified the competent authorities, including the Spanish Data Protection Agency. The investigation, both at an internal level and with our providers, remains ongoing to obtain a complete understanding of what occurred and to take any other necessary measures.
As of the date of this communication, there is no evidence that any fraudulent use has been made of the data affected by the incident, and it is unlikely to result in a high risk to your rights and freedoms. Even so, this unauthorised access to your data by the malicious actor could lead to an attempt on their part to steal or impersonate your identity, publish said data with the corresponding loss of control over them, or use them to carry out phishing attacks or send spam to you. It is for this reason that we recommend you pay special attention to any possible suspicious communications you may receive in the coming days and that you report any anomaly or concerns you may have in this regard through our call centre by calling the following telephone number: 800 760 366.
Likewise, we recommend that you do not provide personal data or sensitive information to people you do not know personally and that, in the event of any suspicion of fraudulent use of your information or data, you bring it to our attention or that of the Spanish law enforcement authorities.
Both the company's operations and services are functioning normally and you may continue to use them.
We apologise for any inconvenience this incident may cause you and reiterate our commitment to security and to compliance with data protection regulations. In any case, if you have any doubts regarding this matter, you can contact the Data Protection Officer of Endesa Energía at the following email address: contactodpo@endesa.es
Should we obtain additional relevant information regarding this incident over the coming days, we will contact you as soon as possible.
Yours sincerely,
Endesa Energía