Incident
Published 2026-09-14
Verified 2026-09-19

Spain AEPD: first notified personal-data breach allegedly executed by an AI agent

Spain's Agencia Española de Protección de Datos (AEPD) blog (14 September 2026; wired by BleepingComputer and SecurityWeek 16 September) says it received the first notification of a personal-data breach in which the incident was allegedly executed by an AI agent using a known large language model. Per the affected organisation's notification (not yet independently verified by AEPD): the agent searched generic files for flaws, completed a successful login, then autonomously probed the application, modified personal data, and accessed invoices. AEPD stresses the report is from the notifier and must be analysed; use of a named model does not imply the model provider was compromised or that the tool was purpose-built for crime. Relevance for defenders: treat agentic chaining (goal → tools → adapt) as a qualitative speed/scale shift for risk analysis, credential/API hygiene, and detection/containment timing — not only for Spanish controllers. Primary: AEPD blog; wires: BleepingComputer, SecurityWeek.

Product
AI agent / LLM-orchestrated attack path against an unspecified controller (notification stage)
Exploited in Australia?
unknown
Patch to
Review IR playbooks for agent-speed chaining; harden credentials/API keys/tokens; shorten detection and containment loops; do not treat AEPD's notice as verified attribution until the agency completes analysis

Primary: AEPD — first notified breach allegedly via AI agent (14 Sep 2026) · Vendor: AEPD (Spanish Data Protection Agency) · BleepingComputer — Spain AEPD AI-agent breach notice (16 Sep 2026)

ai identity