First Notification of an AI-related Breach

First Notification of an AI-related Breach

4 Min Read

On 14 September 2026, the Spanish Data Protection Agency (the “AEPD”) announced that it had received its first notification for a personal data breach which involved an AI agent causing the breach.

What happened?

According to the AEPD’s initial investigation (which it is said is largely based on the report it has received from the data controller) the attacker used an AI tool which started searching for known vulnerabilities on the data controller’s system and made a successful log-in. Once it had accessed the system, it began to search for vulnerabilities in its applications and then used its access to modify personal data and access invoices.

Whilst the AEPD’s report does not say this, we have seen over the years a number of targeted attacks to retrieve invoices usually to divert payments from the company’s bank account to an offshore bank account controlled by a criminal gang. The gangs who are involved in this type of criminal activity are normally very good at social engineering, persuading an organisation to send payments to a different bank account and are often very knowledgeable about the company’s own systems and procedures including the end of a quarter which can help them construct a persuasive narrative.

Is this an isolated incident?

Almost certainly not. The AEPD has made the point that the use of AI in malicious activities is not new and we have already seen GenAI being used to write phishing messages, translate fraudulent campaigns, impersonate identities or to scan for vulnerabilities.

Which tool was involved?

At this stage the AEPD are not telling us the tool that was involved. All that they will say is that it involved “a well-known language model”.

What was the penalty?

We don’t know yet. It’s a GDPR case so there could be a fine of €20 million or 4% of the company’s total worldwide annual turnover but fines in Spain have tended to be on the lower side.

Practical tips on reducing the risk

No organisation is able to remove the risk from this type of attack particularly in the days of ShadowAI, when an organisation is not likely to know the full extent of its AI use. We have also talked about the vulnerability in AI agents which were in common use, for example, OpenClaw which we talked about here OpenClaw Issues Show AgenticAI Dangers and here Gov Info Security: OpenClaw Exposes Hidden Risks in Agentic AI.

Some of the steps an organisation should consider are:

  1. Reading guidance on AI attacks. It is important to concentrate on the realistic rather than the Doomsday scenario which seems to be doing the rounds at the moment. Organisations need to sort fact from fiction and prioritise.
  2. Incorporate AI assisted attacks into your risk analysis. They increase the probability of attacks, their speed and scope.
  3. Review your response times. AI can move more quickly than some solely human attacks. You need to make sure you can match that pace.
  4. Rehearse breaches. Our experience tells us that when a team rehearses a realistic data breach it is better when it comes to dealing with the real thing. We have helped many organisations prepare.
  5. Do work protecting digital identities. This will include account details, log-ins, keys and tokens.
  6. Be aware of the fact that manual intervention is not likely to be enough to prevent these attacks. You will need your defensive technology to be up to date to meet these attacks.
  7. Address the issues with ShadowAI. ShadowAI is certainly an issue that most organisations will have to deal with. Education and training are key but in addition, you will need to employ technical solutions to guard against it.
  8. Be ready to respond 24 x 7 x 365. Many organisations assume and rehearse an attack during working hours. In our experience, that is not very likely. Often the most significant attacks will take place on a Friday evening or over the weekend as the attackers know that is likely to give them more time to do what they want to do unchecked. There is a particular vulnerability over public holiday weekends. Your response plans will need to reflect that.
  9. Don’t assume you are not a target. Using tools like AI keeps the cost of an attack low. Often threat actors won’t need to decide for example whether you are likely to pay a ransom or not because they will use the statistical likelihood that somebody will pay and the low cost of attack. Most businesses are wise to think “when” not “if”.

We are Punter Southall Law, compliance lawyers with expertise in dealing with a data breach.

Our respected team of experienced compliance lawyers is committed to the resolution of complex legal issues in the UK & abroad.

If you require advice, Contact Us to arrange an appointment.

Jonathan Armstrong Lawyer

Jonathan Armstrong

Partner

Jonathan is an experienced lawyer based in London with a concentration on compliance & technology.  He is also a Professor at Fordham Law School teaching a new post-graduate course on international compliance.

Jonathan’s professional practice includes advising multinational companies on risk and compliance across Europe.  Jonathan gives legal and compliance advice to household name corporations on:

  • Prevention (e.g. putting in place policies and procedures);
  • Training (including state of the art video learning); and
  • Cure (such as internal investigations and dealing with regulatory authorities).

Jonathan Armstrong is recognised in The Legal 500 for his work in Data Protection, Privacy and Cybersecurity. The guide notes that “Jonathan Armstrong leads Punter Southall Law’s cybersecurity practice, which is well-positioned to advise on compliance mandates and high-stakes data breaches.”

Jonathan has handled legal matters in more than 60 countries covering a wide range of compliance issues.  He made one of the first GDPR data breach reports on behalf of a lawyer who had compromised sensitive personal data and he has been particularly active in advising clients on their response to GDPR.  He has conducted a wide range of investigations of various shapes and sizes (some as a result of whistleblowers), worked on data breaches (including major ransomware attacks), a request to appear before a UK Parliamentary enquiry, UK Bribery Act 2010, slavery, ESG & supply chain issues, helped businesses move sales online or enter new markets and managed ethics & compliance code implementation. 

Clients include Fortune 250 organisations & household names in manufacturing, technology, healthcare, luxury goods, automotive, construction & financial services.  Jonathan is also regarded as an acknowledged expert in AI and he currently serves on the New York State Bar Association’s AI Task Force looking at the impact of AI on law and regulation.  Jonathan also sits on the Law Society AI Group.

Jonathan is a co-author of LexisNexis’ definitive work on technology law, “Managing Risk: Technology & Communications”.  He is a frequent broadcaster for the BBC and appeared on BBC News 24 as the studio guest on the Walport Review.  He is also a regular contributor to the Everything Compliance & Life with GDPR podcasts.  In addition to being a lawyer, Jonathan is a Fellow of The Chartered Institute of Marketing.  He has spoken at conferences in the US, Japan, Canada, China, Brazil, Singapore, Vietnam, Mexico, the Middle East & across Europe.

Jonathan qualified as a lawyer in the UK in 1991 and has focused on technology and risk and governance matters for more than 25 years.  He is regarded as a leading expert in compliance matters. 

Jonathan has been selected as one of the Thomson Reuters stand-out lawyer – an honour bestowed on him every year since the survey began.  In April 2017 Thomson Reuters listed Jonathan as the 6th most influential figure in risk, compliance and fintech in the UK. 

In 2016 Jonathan was ranked as the 14th most influential figure in data security worldwide by Onalytica.  In 2019 Jonathan was the recipient of a Security Serious Unsung Heroes Award for his work in Information Security.  Jonathan is listed as a Super Lawyer and has been listed in Legal Experts from 2002 to date. 

Jonathan is the former trustee of a children’s music charity and the longstanding Co-Chair of the New York State Bar Association’s Rapid Response Taskforce which has led the response to world events in a number of countries including Afghanistan, France, Pakistan, Poland & Ukraine.

Some of Jonathan’s recent projects (including projects he worked on prior to joining Punter Southall) are:

  • Helping a global healthcare organisation with its data strategy.  The work included data breach similuations and assessments for its global response team.
  • Helping a leading tech hardware, software and services business on its data protection strategy.
  • Leading an AI risk awareness session with one of the world’s largest tech businesses.
  • Looking at AI and connected vehicle related risk with a major vehicle manufacturer.
  • Helping a leading global fashion brand with compliance issues for their European operations.
  • Helping a global energy company on their compliance issues in Europe including dealing with a number of data security issues.
  • Working with one of the world’s largest chemical companies on their data protection program. The work involved managing a global program of audit, risk reduction and training to improve global-privacy, data-protection and data-security compliance.
  • Advising a French multinational on the launch of a new technology offering in 37 countries and coordinating the local advice in each.
  • Advising a well-known retailer on product safety and reputation issues.
  • Advising an international energy company in implementing whistleblower helplines across Europe.
  • Advising a number of Fortune 100 corporations on strategies and programs to comply with the UK Bribery Act 2010.
  • Advising of Financial Services Business on their cyber security strategy.  This included preparing a data breach plan and assistance in connection with a data breach response simulation.
  • Advising a U.S.-based engineering company on its entry into the United Kingdom, including compliance issues across the enterprise. Areas covered in our representation include structure, health and safety, employment, immigration and contract templates.
  • Assisting an industry body on submissions to the European Commission (the executive function of the EU) and UK government on next-generation technology laws. Jonathan’s submissions included detailed analysis of existing law and proposals on data privacy, cookies, behavioural advertising, information security, cloud computing, e-commerce, distance selling and social media.
  • Helping a leading pharmaceutical company formulate its social media strategy.
  • Served as counsel to a UK listed retailer and fashion group, in its acquisition of one of the world’s leading lingerie retailers.
  • Advising a leading U.S. retailer on its proposed entry into Europe, including advice on likely issues in eight countries.
  • Working with a leading UK retailer on its proposed expansion into the United States, including advice on online selling, advertising strategy and marketing.
  • Dealing with data export issues with respect to ediscovery in ongoing court and arbitration proceedings.
  • Advising a dual-listed entity on an FCPA investigation in Europe.
  • Acting for a U.S.-listed pharmaceutical company in connection with a fraud investigation of its Europe subsidiaries.
  • Acting for a well-known sporting-goods manufacturer on setting up its mobile commerce offerings in Europe.
  • Comprehensive data protection/privacy projects for a number of significant U.S. corporations, including advice on Safe Harbor Privacy Shield and DPF.
  • Risk analysis for an innovative software application.
  • Assisting a major U.S. corporation on its response to one of the first reported data breaches.
  • Work on the launch of an innovative new online game for an established board game manufacturer in more than 15 countries.
  • Advice on the setting up of Peoplesoft and other online HR programs in Europe, including data protection and Works Council issues.
  • Advising a leading fashion retailer in its blogging strategy.
  • Advising one of the world’s largest media companies on its data-retention strategy.
  • Advising a multinational software company on the marketing, development and positioning of its products in Europe.

Vivien YanniGan Lawyer

Vivien Yanni Gan

Associate Solicitor

Vivien was admitted as a Solicitor of England and Wales in December 2022. Prior to commencing her training contract she worked in regulatory policy at an investment management firm. She has experience assisting on the implementation of regulatory change projects and advising on risk and regulatory compliance issues in the financial services industry. Vivien also speaks Mandarin.


Related Insights