🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Log in
Back to Resource Center

The biggest cyber attacks in Spain

2026 opened badly for Spanish organisations. In the first weeks of the year alone, a breach at Endesa was confirmed, the Ministerio de Hacienda opened an investigation into an intrusion, and the port of Vigo, gym chain Basic Fit, Inditex and supermarket group Ahorramás were all reported as targets.

The year before was no gentler: Telefónica, El Corte Inglés, Mango, Santander and ING all had customer data exposed. This article covers eight documented cases, what was actually leaked, and the pattern connecting almost all of them.

The biggest cyber attacks in Spain

1. Endesa (2026): 20 million customers claimed

The energy company confirmed a security breach in which personal customer data was exposed, including contact details, DNI numbers, IBAN bank account numbers and contract details. A threat actor operating under the alias “Spain” claimed to have extracted a database of more than one terabyte containing information on over 20 million people.

Endesa notified affected customers, and INCIBE, the Spanish national cybersecurity institute, issued a public advisory.

2. Ministerio de Hacienda (2026): an investigation into 47 million records

The Ministry of Finance investigated a reported intrusion into its databases. According to the attacker, personal, banking and tax data of more than 47 million citizens was compromised. The threat intelligence firm Hackmanac flagged an actor calling itself HaciendaSec. That figure comes from the attacker rather than the ministry, and should be read as a claim rather than a confirmed total.

3. Telefónica (2025): 22 million customer records

The telecoms group suffered a breach that compromised around 22 million customer records. Telefónica is one of the most frequently targeted Spanish organisations, in part because of the volume of subscriber data it holds.

4. El Corte Inglés (2025): the supplier was the way in

On 2 March 2025, El Corte Inglés informed customers that one of its external suppliers had suffered unauthorised access to personal data. Identifying data and payment card details were exposed, though the company stated the leaked card information alone could not be used to make payments.

What followed is the part worth studying. Within days, a smishing campaign began: criminals impersonating the retailer’s financial arm by SMS, aiming to harvest login credentials. The consumer organisation OCU issued a public warning.

5. Mango (2025): also through a supplier

The fashion retailer suffered a breach when its external marketing provider allowed unauthorised access to personal data. The same pattern as El Corte Inglés: the attacker did not go through the brand’s own front door.

6. Booking users (2025): the attack came after the breach

Users of the travel platform were targeted in a campaign combining stolen booking information with convincing follow-up messages. Because the criminals held real reservation details, their messages were far harder to dismiss than generic phishing. This is the clearest example in this list of why stolen data is rarely the end of an incident, but the start of the next one.

7. Santander and ING (2025): thousands of banking customers

Both banks saw customer data compromised. In a sector where a single convincing message can move money, the value of leaked customer data is immediate.

8. The 2026 wave: Vigo, Basic Fit, Inditex, Ahorramás

Beyond the headline cases, the opening weeks of 2026 brought reported incidents at the port of Vigo, gym chain Basic Fit, Inditex and supermarket group Ahorramás. Ports, gyms, retail: there is no longer a sector that reads as an unlikely target.

How does your organisation prevent a major hack?

Most incidents start with one person clicking, opening or approving something. Guardey trains employees to recognise phishing, baiting and social engineering in weekly challenges of three minutes.

Start your free 14-day trial

What these attacks have in common

Two patterns run through this list, and neither is technical.

The supplier is the entrance. At El Corte Inglés and at Mango, the attacker never touched the brand’s own systems. They went through an external provider that held customer data. Your security is only as strong as that of the party you shared your database with, and most organisations have dozens of them.

The breach is the beginning, not the end. The El Corte Inglés case shows it plainly: within days of the leak, criminals were sending SMS messages posing as the company’s financial arm. They had real customer data, which made the message credible. The same happened to Booking users, where genuine reservation details made the follow-up nearly impossible to distinguish from a real message. The leak supplies the ammunition; the attack that costs money comes later, and it targets people.

That second stage is where an organisation can still intervene. A firewall cannot stop an employee acting on a message that contains accurate information about a real transaction. A trained employee can. It is the same mechanism behind baiting: the attacker supplies a reason to act, and the decision happens in seconds.

How to protect your organisation

Backups, patching and access control are the baseline. Beyond that, three things matter for the patterns above:

  • Audit who holds your data. If a marketing provider or logistics partner has your customer database, their security is now your risk. Ask what they do about awareness training, not just encryption.
  • Train for the second wave. Assume data will leak somewhere, some day. What decides the damage is whether your staff recognise the convincing message that arrives afterwards.
  • Practise instead of instruct. Realistic phishing simulations show which departments need support before an attacker finds out for you.

For organisations under NIS2, awareness training is no longer optional. It is named explicitly in the directive, and our NIS2 guide covers what that means in practice.

See where your risk actually sits

In a 45-minute demo we show how Guardey combines weekly awareness training with realistic phishing simulations, and how the reporting pinpoints the departments that need support.

Schedule a personal demo
Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo