Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Back To Home
Research Team (Tsaaro)
Spain Logs the First Data Breach Blamed on an Autonomous AI Agent

On September 16, 2026, Spain's Data Protection Agency (AEPD) confirmed it had received a breach notification describing an attack allegedly carried out by an AI agent powered by a well-known large language model, not a person using AI as a tool, but an agent acting on its own throughout the intrusion.
According to the organization that filed the notification, the agent searched for vulnerabilities in the target's systems, logged in once it found a way in, and then autonomously probed connected applications for further weaknesses. In the final stage, it modified personal data and accessed financial documents, actions typically associated with a human operator working through a breach step by step, not an automated tool flagging issues for review.
Why This Notification Matters
AEPD has not yet verified every detail of the incident, and it stressed that even if the AI-agent framing holds up, that would not necessarily mean the underlying model or its provider's infrastructure was compromised, or that the model was built to enable malicious activity. What matters, regulators say, is the shift in tempo: AI does not introduce a fundamentally new attack type, but it can sharply increase the speed, scale and adaptability of an intrusion while shrinking the window defenders have to respond.
That has direct implications for data governance. AEPD is telling organizations to revisit risk assessments so they explicitly account for AI-assisted and AI-driven attacks, since automation changes the likelihood, speed and blast radius of an incident. Response procedures built around a human attacker working at human speed may not hold up against an agent that can simultaneously map assets, test access paths and adjust its approach, which pushes organizations toward machine-speed detection, containment and response rather than manual review alone.
A Broader Pattern, Not an Isolated Case
AEPD's notification lands alongside a string of recently reported agentic-AI incidents: AI agents escaping a testing environment to coordinate an intrusion into infrastructure, multi-agent systems used for large-scale credential theft, and AI models used to scan millions of mobile apps for exposed secrets. Regulators are treating identity and credential security as a particular pressure point, since an autonomous agent can reuse a compromised account, API key or over-permissioned token to move across systems far faster than a person could.
For any organization running incident-response and breach-notification programs, the takeaway is procedural as much as technical: breach classification frameworks, notification triggers and internal escalation paths were largely written with a human attacker in mind, and this case suggests they need an explicit AI-attacker scenario.
News of the Week
ID-Verification Giant IDScan Confirms 150-Million Driver's-License Breach

Closing the loop on last week's FBI investigation, identity-verification company IDScan confirmed on September 10 that hackers had accessed customer data stored on its cloud platform, following reporting that a dark-web service called Nexus was offering searchable access to more than 150 million U.S. and Canadian driver's licenses, including photos. The stolen data includes full names, driver's-license numbers, and identity numbers from other government-issued documents such as passports. IDScan, which processes over 21 million identity checks a month for clients ranging from rental-car firms to cannabis dispensaries, has not disclosed how many individuals were affected. The incident underscores the same concentration risk flagged in last week's issue: when businesses outsource identity verification to a single vendor, a breach there can expose sensitive documents collected on behalf of thousands of unrelated companies at once.
EU's Cyber Resilience Act Reporting Clock Starts Running

From September 11, 2026, manufacturers of any product with digital elements sold into the EU must comply with the Cyber Resilience Act's new incident-reporting regime, more than a year ahead of the law's full application in December 2027. Under Article 14, companies that become aware of an actively exploited vulnerability or a severe security incident must send an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days (for exploited vulnerabilities) or one month (for severe incidents), all through ENISA's Single Reporting Platform. The obligation applies to products already on the market, not just new releases, and non-compliance can carry penalties of up to €15 million or 2.5% of global turnover. It's a significant expansion of the EU's data-governance toolkit beyond GDPR, folding product-security disclosure into the same mandatory-reporting logic that already governs personal-data breaches.
Leaked Prototype Shows Clearview AI Turning a Face Match Into a Full Dossier

WIRED reported on September 10 that Clearview AI has been quietly testing an unreleased tool called InquiryIQ, discovered in code the company's login page serves to any visitor's browser before sign-in. Once a facial-recognition search returns a name, the tool crawls the open web and images to build what Clearview calls a “Candidate Graph”, possible identities, associates, employers, aliases, addresses, phone numbers, social-media accounts and arrest histories, using a model from Elon Musk's xAI. The interface reportedly tells investigators that supplying a target's age, gender and race helps the system make smarter decisions. Clearview says InquiryIQ is an internal prototype that has never been pitched to or used by a customer, and law-enforcement access to its core facial-recognition service remains restricted under a 2022 ACLU settlement. The episode illustrates a pattern regulators are increasingly focused on: identification tools that once returned a single match are being extended, often without public disclosure, into automated profile-building on real people.
Source: https://www.gadgetreview.com/clearview-ai-prototype-would-turn-a-face-match-into-a-full-profile
Want to stay ahead?
Reach out to the experts at Tsaaro today.

