decrypted · 18 september 2026 · vulnerabilities and patching · uk policy and law · ai and llm security
An AI agent hacked a company on its own, and the UK already wrote the fix
Spain's data protection authority has logged what looks like a first: a personal data breach carried out by an AI agent working alone, chaining together a login, a vulnerability hunt and a data grab with no human walking it through each step. The report is preliminary and the company involved hasn't been named, but the mechanics described are exactly the scenario the UK's National Cyber Security Centre warned about a month ago, and they are a useful stress test for anyone in a UK boardroom currently signing off an agentic AI pilot.
What the agent actually did
According to the AEPD's account, the attack began with the agent scanning generic files for weaknesses, then logging in with valid credentials. From there it searched the target application on its own, found a flaw, and used it to alter personal data and pull invoices. Nobody was driving each step. Picture a break-in where the burglar does not need to case the building, pick the lock and then separately work out where the safe is: one continuous process handles reconnaissance, entry and theft, at whatever speed the hardware allows.
The AEPD is careful to say this account comes from the affected organisation and has not been independently verified, and that using a particular AI model does not mean that model or its provider's infrastructure was compromised. But the direction of travel matches what security researchers have reported all year: agents chaining tool use, code execution and adaptive decisions into attacks that used to need a human operator at every stage.
The lesson the NCSC already published
The useful part, for UK organisations, is that the NCSC did not wait for an incident like this to say what good practice looks like. Its interim guidance on agentic AI, published in August, tells organisations to give each agent its own identity rather than borrowing a human's, keep its permissions to the minimum the task needs, use credentials with the shortest possible lifetime, sandbox anything high-risk with network access denied by default, and keep the ability to pull the plug on an agent immediately if something looks wrong.
None of that is exotic. It is the same least-privilege, defence-in-depth thinking Secure by Design has always asked for, applied to a new class of user that operates at machine speed and never gets tired or careless. The Spanish case may turn out to be one company's misconfigured pilot rather than the vanguard of a new attack class. Either way, the guidance for avoiding it already exists, and the organisations that will fare best are the ones that treated it as policy before they had a reason to.
Also this week
Check Point's VPN flaws just got more urgent. CVE-2026-85102 and CVE-2026-85103, critical certificate-validation and heap-overflow bugs in Check Point's VPN gateways, were unexploited when patches shipped on 9 September. The Dutch NCSC and CERT-EU have now assessed exploitation as imminent, rating both likelihood and impact high, even though Check Point still reports no evidence of active attacks or public proof-of-concept code. If your gateways are still unpatched, this is the week that stops being optional.
Ofcom can fine platforms, it just can't collect. The regulator's director of enforcement confirmed this week that most of the roughly £7 million it has levied under the Online Safety Act, including a £1.4 million penalty against 8579 LLC, remains unpaid, because platforms with no UK assets are hard to chase for debt. It is a reminder that a law's deterrent value rests on enforcement mechanics as much as on the fines it allows, worth keeping in mind as age verification and AI platform investigations under the same Act continue.
Sources
- AEPD: Primera notificación de una brecha de datos personales causada por un ataque ejecutado mediante agente de IA
- Spain reports first data breach involving autonomous AI agent
- Spain's data agency gets first report of AI-powered data breach
- Managing the cyber risk of agentic AI
- Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
- Ofcom discovers issuing Online Safety Act fines is easier than collecting them
Thinking about how to govern an agentic AI pilot safely? Get in touch.
More like this
- Cisco's network gatekeeper let attackers in without a login 17 september 2026
- A crafted email is all it takes to root Cisco's mail gateway 15 september 2026
- The AI test that broke into a real company because it couldn't stop 11 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.