[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / Cyberattacks

Spain's data agency receives first report of an AI-assisted breach

Spain's data protection agency received a report alleging that an AI agent found vulnerabilities, accessed systems, changed personal data and viewed invoices. The agency has not investigated or verified the report, so the incident details remain developing.

All updates
Reported DevelopingPublished 21 September 2026

Incident timing: The report was received by AEPD before its September 16, 2026 public discussion. The source does not establish when the alleged intrusion occurred.

Spain's data protection agency said it received a notification describing an alleged breach carried out with help from an AI agent. The report says the agent searched for weaknesses, logged into systems, modified personal data and accessed financial documents. The agency has not yet verified the account, so organizations should treat the case as an early signal about faster automated intrusion workflows rather than a confirmed description of a specific attack.

Source & attribution

Read the original reporting at BleepingComputer

AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.

Editorial policy & corrections