ACVE-2026-0538
An AI agent used by an attacker logged in to an organisation's application, modified personal data and accessed invoices, in the first such breach notified to Spain's data regulator.
Exposure
Reproducibility: partial (model availability not checked (no registry reference); trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
The exposure axes marked confirmed were matched to the first-hand sources listed above.
Description
Threat
user · unsafe-default · harmful-action
What
Spain's data-protection regulator, the AEPD, published the first breach notification it has received for an attack carried out through an AI agent that used a well-known language model, which it does not name. According to the affected organisation's notification, a third party used the agent as an instrument to chain the phases of the attack: it searched generic files for vulnerabilities and logged in successfully, then autonomously searched the application for vulnerabilities, which let it modify personal data and access invoices. The AEPD does not name the organisation, does not say how the login was obtained or whether the data was restored, and cautions that using a specific model does not imply the model or its provider was compromised.
Detection
The AEPD says the information comes from the organisation's notification and still has to be analysed. Recorded from the AEPD's post. Not recreated in a lab.
Fix
Protect credentials and digital identities, add rapid detection and containment, and keep high-impact actions under human control.
Fix
The attacker ran the agent, so the controls that protect victims are the targeted organisation's credential protection and fast detection, and the model provider's misuse detection.
- Reconfigure
model-provider.misuseDetectiontodetects agents attacking third-party applications. Recommended: the attacker chained login, vulnerability search and data changes through one agent. Owner: model-provider - Reconfigure
application.logintostrong credential and identity protection. The targeted organisation's application accepted the agent's login; the AEPD recommends protecting credentials. Owner: operator - Reconfigure
application.monitoringtofast detection and containment of automated attacks. The agent searched the targeted organisation's application on its own; the AEPD recommends fast detection and containment. Owner: operator