The report
Spain's data-protection authority, AEPD, says it received its first personal-data-breach notification in which the reported attack was executed through an AI agent using a known large language model. The case is important because it reached a regulator as a real breach notification, but the public record is still incomplete and under review.
AEPD's September 14 blog listing identifies the notification as the authority's first of this type. Reuters' September 15 report adds the sequence attributed to the affected organization: the agent logged into a system, searched for application weaknesses, identified a vulnerability, modified personal information and viewed billing records. AEPD characterized the reported operation as involving limited human intervention across multiple stages.
That sequence should not be stretched beyond the evidence. The public sources do not identify the affected organization, the model or provider, the vulnerability, the credential-acquisition path, the number of affected people or a quantified exfiltration event. AEPD had not announced a final determination in the cited reporting.
The regulator also cautioned against a different shortcut: use of a particular model does not by itself mean that the model or the provider's infrastructure was compromised, nor that the model was developed for malicious use.
For Digging Beagle, this is therefore a regulatory milestone rather than a completed forensic story. The dossier keeps the organization's notification, the regulator's review status and the unresolved technical questions separate. If AEPD later identifies the controller, model, vulnerability or impact, those should be added as later evidence rather than retrofitted into the original notification.