glock is the alias of a likely lone, Spanish-speaking cybercriminal associated with the January 2026 attempted sale of data allegedly stolen from Endesa, a major Spanish electricity and gas provider. The actor also used the alias spain and appears to have had only a limited presence on low-barrier underground forums, with no evidence of a broader team, affiliate structure, or sustained operational history. The activity attributed to glock centered on unauthorized access to customer-related data and subsequent attempted monetization through underground database-trading forums. The operation appears to have been focused on data theft and sale rather than ransomware deployment, encryption, or disruptive sabotage. Reported victim data included personal, contractual, and financial information associated with energy customers. After the victim organization did not engage, the actor reportedly escalated pressure by threatening further release of data, but available reporting did not establish completed sales or a mature extortion program. Available analysis assessed the most likely initial access vector as the use of compromised legitimate credentials, potentially including elevated employee or service access. The intrusion likely involved abuse of privileged application or integration access to extract large volumes of backend customer data, with indications of access extending beyond ordinary CRM usage. This supports capabilities in initial access through credential compromise, post-compromise access abuse, privilege use within enterprise platforms, and data exfiltration. There is no high-confidence evidence that glock conducted ransomware encryption, destructive actions, or operational disruption in this incident. The actor’s known activity is currently limited to this Endesa-related case, and no formal state attribution or linkage to a larger named intrusion set is established. The available evidence is most consistent with a financially motivated criminal actor seeking to profit from stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.