Spanish Data Protection Agency identifies first reported data breach carried out by an AI agent.

September 16, 2026

The potential of AI to be used to effect a data breach has been well known for some time.  Now the Spanish data protection agency has identified a data breach caused by a large language model identifying vulnerabilities and then gaining access to a system.   When inside the AI agent modified personal data and acccess invoices.  This has been long expected.  It does not mean that cyber defences are now useless.  It does mean that care should be taken to look at vulnerabilities, patch as soon as advised that upgrades are required and have a multi layered defence.  AI is not a magic bullet.  It is a means by which vulnerabilities can be identified quickly and exploited.  It does create vulnerabilities.

The Reuters article on this development provides:

MADRID, Sept 15 (Reuters) – Spain’s data protection watchdog said it has received the first reported notification of a personal data breach allegedly carried out by an artificial intelligence agent, a case that suggests autonomous ?systems are beginning to play a direct role in cyberattacks.
The Spanish Data Protection Agency (AEPD) ?said on Monday in a blog on its website that the incident involved an AI agent using a widely known large language model to identify vulnerabilities, gain access to a system and subsequently modify personal data and access ?invoices.

Read the rest of this entry »

SA Health data breach over employee accessing Tony Modra’s medical records. Highlights the generally poor record of the health sector in maintaining data security

September 15, 2026

The Health sector consistently tops the list of sectors that suffer the most data breaches.  Some of those data breaches have been very large and public, ransomware attacks affecting thousands of patients, and others more isolated, staff accessing records they are not authorised to view.  All data breaches are serious.  The ABC reports that a South Australian health employee has been reprimanded for accessing Tony Modra’s health records. Modra is a former South Australian AFL player.  In South Australia that is a very big deal.  So is accessing his data without lawful excuse.

The story was first reported on 24 July 2026. That story also highlighted SA Health’s previous problems with data security with staff accessing medical records in 2016 and 2024.  Both previous occasions the access related to notorious cases.

South Australia has no privacy legislation.  The only state without legislation.  it regulates through a Cabinet Administrative Instruction titled Information Privacy Principles Instruction, Premier and Cabinet Circular 12t.  That is binding on South Australian state government agencies and the public sector. Complaints have to be made to the Privacy Committee of South Australia.  It is a wholly ineffective process.  It has no enforcement powers.  

A reprimand for a breach of this nature is inadequate.

This is a case where Modra may have a claim under the Commonwealth’s statutory tort of serious invasion of privacy.  The act was a misuse of private information and it was intentional.  There was also a reasonable expectation of privacy.  There is a 12 month limitation period which must always be borne in mind in cases of this nature.

The article provides:

One SA Health employee has been reprimanded for accessing AFL legend Tony Modra’s private medical records after he was seriously injured in a truck crash, while two other employees remain under investigation, the health department says.

In a statement, SA Health said another six people were no longer being investigated.

“The number of employees under investigation for potentially accessing a patient’s medical record inappropriately has been revised from nine individuals, to three,” the statement said.

“Of these three, one individual has been reprimanded and two are still being investigated.

“Six individuals are no longer under investigation for this matter.”

Any sanction imposed becomes part of an employee’s permanent record. Read the rest of this entry »

Misuse of CCTV surveillance highlights privacy breach potential of the technology

September 14, 2026

The Victorian Police Force has a dreadful record when it comes to privacy.  Officers have misused the LEAP databases on multiple occasions (that we are aware of).  See my posts here.  They breached Dani Laidley’s privacy by taking pictures inside a police station.  See my posts here. It is a cultural problem that has not been properly, if at all, addressed over many years.

The latest privacy breach involving a member of the Victoria Police, Sam Hansen, using CCTV to monitor his partner, if that is the right descriptor.  Hansen received a diversion.  Given the nature of the offence and the breach of trust that is a good result for him but questionable as to whether it is the appropriate penalty.

There are also the civil issues.  Victoria Police use of surveillance, CCTV and personal data acquired from its use is covered by the Information Privacy Principles (IPPs) under the Privacy and Data Protection Act 2014.  There is an exemption  under Section 15 which permits non-compliance for legitimate law enforcement, criminal investigations, or covert surveillance functions. The Victorian Civil and Administrative Tribunal (VCAT) has jurisdiction regarding breach of the Act.  

It is very disappointing that VCAT’s decisions over the years have meant that recourse under the Privacy and Data Protection Act 2014 is difficult at the best of times.  VCAT has a very poor reputation in handling privacy cases and where claimants are successful, not often, the awards are miserly. Whenever possible it would be better to use Schedule 2 of the Privacy Act 1988, the statutory tort of serious invasion of privacy.

While all the facts in this case are not known what is known indicate there is a basis for bringing an action under this new tort.  The acts of Hansen were intentional.  Just because the CCTV may have been used in a public place that does not negate a person’s reasonable expectation of privacy and the harm is serious.  It is hard to Read the rest of this entry »

Another Council looks to ban smart glasses on its premises. This time Yarra Council wants to ban smart glasses from pools, gyms, playgrounds and childcare centres. Big statement, enforcement will be interesting

September 9, 2026

Last night Yarra Council passed a motion to “investigate” banning smart glasses at Council leisure centres, childcare centres and playgrounds.

Such a broad ban with carve outs for people with low vision or other disabilities would be difficult to enforce. Ray ban style glasses are quite common and while smart glasses can be distinguished from other sun glasses that requires a council officer coming quite close.

The motion that was passed by Councillor Wade is that Council:

  1. Obtain a report before the end of this calendar year on: (a). Updating Council’s conditions of entry and other policies to ban the use of smart glasses” at Council’s leisure centres and all council – run childcare centres and playgrounds, subject to any necessary carve outs for deaf, law vision or disabled users; and 

    (b)   communicating this change in policy to users and relevant stakeholders, including installing signage as necessary.

  2. Advocate to the federal government for updates to the Privacy Act to ensure it is fit for purpose and able to respond to the risks of new wearable technology, and for a temporary ban on smart glasses imports, until Australia’s privacy and data collection laws are updated to better protect our communities.

While the Council motion is correct about the Privacy Act requiring more reform there is still scope to bring an action for the tort of serious invasion of privacy through the use of such glasses in certain situations.  Such glasses act in an indentical way as a camera or video, which can be misused.

The Yarra Council statement provides:

Last night, Council endorsed a motion to investigate banning smart glasses at Council leisure centres, childcare centres and playgrounds.

Yarra City Council Mayor Cr Stephen Jolly says smart glasses are a rapidly evolving technology, and it is council’s responsibility to protect the community’s privacy in all council-run spaces.

“Our spaces need to be safe and respectful – especially for the more vulnerable members of our community,” he says.

“This is about protecting people’s privacy, particularly in places where children and families come together,” the Mayor says.

Council resolved to investigate this further, with carve outs for people living with disability who may need this technology to go about their daily lives.

Council will also call on the federal government to bring in stronger privacy laws to further protect people from these new technologies.

The ABC report, Yarra council bans smart glasses from pools, gyms, playgrounds and childcare centres, exaggerates what the motion actually states.  There is no ban as such.  There will be an investigation into a ban.  The ABC sought quotes from participants Read the rest of this entry »

More than one million people affected by data breach of Mathspace in Australia and New Zealand. While the data breach is serious Mathspace announcement is excellent and provides real information to customers rather than the usual boilerplate organisations often adopt

Any online service needs to give priority to security.  That is all the more important for health and educational services.  Mathspace is an online service. Unfortunately   Mathspace has suffered a significant data breach.  More than a million people have been affected, including students and staff.   The source of the breach is a vulnerability in the system which was identified and a patch was issued on 6 August 2026   The hackers took advantage of the vulnerability on 10 August 2026.  Mathspace installed the patch on 29 August 2026 when prompted by the program’s creater.  Data was exfiltrated on 27 August 2026.

The key lesson here is that every patch and update an organisation receives needs to be installed as soon as possible after receiving it.  Sometimes that is automatically done, but it needs to be checked.  That is a process issue.

Yesterday the Mathspace announced the data breach on 3 September 2026. The announcement is very good.  It sets out what happened, how many people have been affected and what is being done.  It delves Read the rest of this entry »