AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

September 14, 2026

An unnamed organization has notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people. … through JOIN US.
Alleged deployer
threat-actors, cybercriminals, ai-agent-system-deployers, agentic-threat-actors
Alleged developer
large-language-model-developers, ai-agent-system-developers
Alleged harmed parties
victims-of-automated-cybercrime, privacy, organizations, organization-affected-by-ai-agent-data-breach-reported-to-aepd, information-security, enterprise-it-systems

AI governance case studies

For forensic AI governance failure analysis (TAIMScore™ case studies), browse Human Signal’s Failure Files™.

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1693

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.