AIPolicyTracker

AI incident ·

AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

4 news reports Synced from source · record last edited 17 Sep 2026

In brief

An AI system built by Large language model developers and AI agent system developers and deployed by Threat actors, Cybercriminals and 2 others allegedly harmed Victims of automated cybercrime, Privacy and 4 others.

Risk domain
Not classified
Occurred
Coverage
4 reportsSep 2026

What happened

An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (4)

Titles link to the original publisher; report text is not reproduced here.

Who was involved

Alleged harmed party
Victims of automated cybercrime Privacy Organizations Organization affected by AI-agent data breach reported to AEPD Information security Enterprise IT systems

AI systems implicated

Large language modelsAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Other incidents involving Threat actors

Source record: incident #1693 on the AI Incident Database · all 4 reports