{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0538",
  "aliases": [],
  "published": "2026-09-14T00:00:00Z",
  "firstReported": {
    "date": "2026-09-14",
    "url": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia",
    "publisher": "Francisco Pérez Bes, AEPD"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "An AI agent used by an attacker logged in to an organisation's application, modified personal data and accessed invoices, in the first such breach notified to Spain's data regulator.",
  "details": "## What\n\nSpain's data-protection regulator, the AEPD, published the first breach notification it has received for an attack carried out through an AI agent that used a well-known language model, which it does not name. According to the affected organisation's notification, a third party used the agent as an instrument to chain the phases of the attack: it searched generic files for vulnerabilities and logged in successfully, then autonomously searched the application for vulnerabilities, which let it modify personal data and access invoices. The AEPD does not name the organisation, does not say how the login was obtained or whether the data was restored, and cautions that using a specific model does not imply the model or its provider was compromised.\n\n## Detection\n\nThe AEPD says the information comes from the organisation's notification and still has to be analysed. Recorded from the AEPD's post. Not recreated in a lab.\n\n## Fix\n\nProtect credentials and digital identities, add rapid detection and containment, and keep high-impact actions under human control.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "unnamed-ai-agent"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-693"
      ],
      "noCveReason": "No code defect is established: the report describes an attacker-directed agent operation.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "harmful-action"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/"
        }
      ],
      "fix": {
        "summary": "The attacker ran the agent, so the controls that protect victims are the targeted organisation's credential protection and fast detection, and the model provider's misuse detection.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "model-provider.misuseDetection",
            "to": "detects agents attacking third-party applications",
            "why": "Recommended: the attacker chained login, vulnerability search and data changes through one agent.",
            "owner": "model-provider"
          },
          {
            "type": "reconfigure",
            "target": "application.login",
            "to": "strong credential and identity protection",
            "why": "The targeted organisation's application accepted the agent's login; the AEPD recommends protecting credentials.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "application.monitoring",
            "to": "fast detection and containment of automated attacks",
            "why": "The agent searched the targeted organisation's application on its own; the AEPD recommends fast detection and containment.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "An AI agent, not named by the regulator",
          "any": false,
          "status": "confirmed",
          "source": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia"
        },
        "model": {
          "value": "A well-known language model; the regulator withholds its name",
          "any": false,
          "status": "confirmed",
          "source": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia"
        },
        "goal": {
          "value": "Any attacker-directed task that can use login, discovery and data-access tools",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Vulnerability searching across generic files and the application, and a working login to the application; no tools are named",
          "status": "confirmed",
          "source": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia"
        },
        "approval": {
          "value": "The regulator says the agent searched for vulnerabilities autonomously; no approval mode is stated",
          "mode": "unknown",
          "status": "confirmed",
          "source": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia"
        },
        "inputControl": "operator",
        "agentAction": "The agent logs in, searches the application for vulnerabilities on its own, and uses them to modify personal data and access invoices.",
        "harm": "data-exfiltration",
        "divergence": "decomposed-misuse",
        "reach": {
          "value": "Personal data and invoices in the affected organisation's application",
          "kinds": [
            "network"
          ],
          "status": "confirmed",
          "source": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia"
        },
        "condition": {
          "value": "After a successful login, when the agent autonomously searched the application for vulnerabilities",
          "status": "confirmed",
          "source": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia"
        },
        "recovery": {
          "value": "Not reported: the regulator does not say whether the modified data was restored or the incident contained.",
          "outcome": "unknown",
          "status": "unconfirmed"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "researcher",
        "primary": [
          {
            "url": "https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia",
            "kind": "researcher-report",
            "party": "Francisco Pérez Bes, AEPD (Spanish data-protection regulator)"
          }
        ]
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/",
            "type": "news",
            "note": "SecurityWeek reports an AEPD breach notification."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
