SOURCE-LINKED INTELLIGENCE
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.
Read original source ↗ Open in workspace
- recordType
- incident-report
- evidenceStatus
- reported
- region
- Global
Reported occurrence date: 2026-09-14T00:00:00.000Z
Evidence & attribution
- AI Incident Database · 2026-09-14T00:00:00.000Z
AI Incident Database, Responsible AI Collaborative; McGregor (2021), Preventing Repeated Real World AI Failures by Cataloging Incidents. Incident-specific contributor credits are available at each citation link. Metadata adapted; article text excluded.
License: CC BY-SA 4.0
First collected: 2026-09-22T16:03:50.148Z. This is not the publication date.