Incident
Published 2026-09-14
Verified 2026-09-19

Spain AEPD: first notified personal-data breach allegedly run by an AI agent (LLM)

Spain’s Agencia Española de Protección de Datos (AEPD) blog (14 September 2026; Francisco Pérez Bes) reports the agency’s first notification of a personal-data breach in which the incident was allegedly executed by an AI agent using a known large language model. Per the notifier: the agent searched generic files for vulnerabilities, successfully logged in, then autonomously hunted application flaws, modified personal data, and accessed invoices. AEPD stresses the claim is from the organisation’s notification and still requires analysis; use of a given model does not imply the provider’s model or infrastructure was compromised or purpose-built for crime. Framing: shift from AI-assisted attacker tools (phishing copy, vuln search) toward agentic chaining of attack phases at machine speed — with implications for identity/credential controls, detection, and response timing. National Cryptologic Center (CCN) paradigm-shift context noted in wire coverage. Primary: AEPD blog; secondary: BleepingComputer 16 Sep 2026.

Product
AI agent / LLM used as offensive automation (incident notification; not a product CVE)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Operators: treat agentic offence as faster/adaptive; tighten identity, API keys, and least privilege; accelerate detect/contain playbooks beyond manual-attack assumptions (per AEPD framing)

Primary: AEPD — primera notificación brecha por agente de IA (14 Sep 2026) · Vendor: AEPD blog (Spanish DPA) · BleepingComputer — Spain AEPD first AI-powered breach report (16 Sep 2026)

ai identity