AI incident #1693 ·

AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

Open on the AI Incident Database 4 news reports Synced from the AIID API · record last edited 17 Sep 2026

What happened

An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (4)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

Who was involved

Alleged harmed party
Victims of automated cybercrime Privacy Organizations Organization affected by AI-agent data breach reported to AEPD Information security Enterprise IT systems
On AIID: Victims of automated cybercrime, Privacy, Organizations, Organization affected by AI-agent data breach reported to AEPD, Information security, Enterprise IT systems

AI systems implicated

Large language modelsAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries

Other incidents involving Threat actors