Weekly Cybersecurity Digest [September, Week 3]

Posted on September 22, 2026

Dear Valued Clients,

Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent developments show how cyber risk is expanding across autonomous AI, sensitive-data exposure, targeted surveillance, operational disruption, and cross-border resilience.

Spain’s data-protection authority received what it described as the first reported personal-data breach allegedly carried out by an AI agent, LMU Munich disclosed unauthorised access to sensitive student data, and UK and Dutch authorities exposed an Iran-linked spyware campaign targeting high-risk individuals. At the same time, new research shows ransomware pressure increasing sharply against European manufacturers, while EU institutions are focusing more closely on information sharing, coordinated response, and accountability for sensitive data.

✅ Top Stories of the Week

i. Spain Reports First AI Agent-Linked Personal Data Breach

Spain’s data-protection authority received what it described as the first reported notification of a personal-data breach allegedly executed by an AI agent. According to the affected organisation’s report, the agent identified application weaknesses, gained access, modified personal information, and viewed billing records with limited human intervention. The case remains under review, but it provides an early real-world example of how increasingly autonomous tools may compress the time available for organisations to detect and contain malicious activity. [Read more via Reuters]

ii. Cyberattack Exposes Sensitive Student Data at LMU Munich

Ludwig Maximilian University of Munich confirmed on September 19 that an attacker accessed student-registration data and that the university must assume the data was retrieved. Potentially affected information includes names, addresses, bank details, health-insurance numbers, BAföG identifiers and, in some cases, special-category personal data connected to leave-of-absence reasons. LMU isolated the affected system, while teaching continued. [Read more via LMU]

iii. UK and Netherlands Expose Iran-Linked CHOSEN BRICK Spyware Campaign

The UK’s National Cyber Security Centre, together with US and Dutch authorities, warned that Iran-linked actors are using spyware known as CHOSEN BRICK against dissidents, activists, and journalists. Attackers reportedly build trust through highly tailored social engineering before delivering malicious files disguised as legitimate material, including fabricated medical documents. The campaign demonstrates how targeted surveillance increasingly combines technical compromise with extensive personal reconnaissance and psychological manipulation. [Read more via UK National Cyber Security Centre]

✅ Industry Trends & Insights

North Korean Campaign Uses Fake Tech Jobs to Infect Thousands of Devices

A new international advisory linked the North Korean WaterPlum campaign to at least 30,000 infected devices across 100 countries and more than $10.5 million in stolen cryptocurrency. Attackers pose as AI or blockchain companies and target developers, engineers, and other technology professionals through recruitment and freelance platforms before delivering malware during supposed interview processes. German law enforcement participated in the advisory, while investigators also linked the campaign to broader North Korean efforts to gain employment inside technology firms in Europe and elsewhere. [Read more via The Record]

Ransomware Attacks Against European Manufacturers Surge

New research found that ransomware attacks against manufacturers increased sharply, with European targets rising by 85%. Germany recorded the highest number of attacks in Europe, followed by Italy, the UK and France. The trend highlights how manufacturing remains a high-value target because disruption can quickly affect production, suppliers, and wider supply chains. [Read more via SecurityWeek]

✅ Regulatory & Policy Updates

Ireland Fines Google €403 Million Over Location Data Processing

Ireland’s Data Protection Commission imposed fines totalling €403 million on Google following an investigation into the processing of location information through features including Web & App Activity, Location History, and Location Accuracy. The regulator found GDPR infringements involving lawfulness, fairness, transparency, accountability, and retention, and ordered Google to bring its processing into compliance within six months. The decision reinforces that location information requires particularly careful governance because it can reveal detailed patterns about individuals’ movements and behaviour. [Read more via Irish Data Protection Commission]

EU Auditors Warn Poor Information Sharing Is Weakening Cyber Defences

The European Court of Auditors warned that insufficient and delayed information sharing between EU Member States is undermining collective cyber response. Its report found that serious incidents affecting several countries are not consistently reported through EU coordination mechanisms, limiting the ability of ENISA and other authorities to build a complete picture of cross-border threats. For organisations and authorities alike, the finding reinforces that effective incident response depends not only on detecting an attack internally but also on sharing relevant information quickly enough for others to act. [Read more via Reuters]

EU Proposes Emergency Security Protocol for Cyber and Hybrid Threats

European Commission President Ursula von der Leyen proposed a new Emergency Security Protocol that would allow any EU Member State to convene all 27 governments in response to serious cyberattacks, sabotage, drone incursions, and other hybrid threats. The mechanism would be designed to coordinate a European response, limit the impact of an incident, and deter further escalation. The proposal reflects growing concern that existing EU decision-making structures may be too slow for fast-moving cross-border security threats. [Read more via The Record]

✅ Cyber IQ Challenge + Proactive Security Hacks

Quick Quiz: An organisation deploys an AI agent that can access internal systems and modify business records. Which approach provides the strongest security control?

A) Give the agent broad access so it can operate efficiently
B) Rely entirely on safeguards provided by the AI vendor
C) Apply least privilege, scoped credentials, human approval for high-impact actions, and detailed activity logging
D) Disable logging to reduce the amount of sensitive information retained

(Answer below)

Smart Security Moves of the Week:

  • Constrain AI-agent permissions: Treat autonomous tools as privileged identities. Limit accessible systems, data, and actions, and require human approval for high-impact changes.
  • Protect high-risk individuals: Provide enhanced device monitoring, phishing-resistant authentication, and clear escalation channels for executives, researchers, journalists, activists, or others likely to face targeted surveillance.
  • Review membership and community databases: Organisations holding large member datasets should minimise retained information, restrict administrative access, and include external website providers in security reviews.
  • Monitor software at runtime: Dependency scanning should be complemented by behavioural controls capable of detecting packages that appear clean during installation but execute malicious functionality later.
  • Strengthen incident-sharing procedures: Define what information can be shared with regulators, CSIRTs, sector partners, and affected third parties, and resolve legal or classification barriers before a major cross-border incident occurs.
  • Review location-data retention: Organisations processing movement or location information should verify that collection is necessary, transparent, appropriately secured, and retained only as long as required.

Answer: C) Apply least privilege, scoped credentials, human approval for high-impact actions, and detailed activity logging.

AI agents should be treated as active system identities rather than passive software. The greater their autonomy, the more important it becomes to limit what they can reach, preserve evidence of what they did, and keep meaningful human control over consequential actions.

✅ Conclusion

This week’s developments show how cyber risk is becoming both more autonomous and more interconnected. AI agents may increasingly participate directly in attack activity, targeted spyware campaigns combine technical compromise with highly personalised social engineering, and ransomware continues to place pressure on European manufacturing and supply chains.

The European response is also becoming more coordinated. Ireland’s €403 million GDPR fine against Google reinforces expectations around sensitive-data governance, while EU auditors have highlighted weaknesses in cross-border cyber information sharing. The proposed Emergency Security Protocol adds another dimension, reflecting growing attention to how Member States coordinate responses to serious cyberattacks and wider hybrid threats.

Final reflection: As cyber incidents become faster, more interconnected and increasingly capable of crossing organisational and national boundaries, does your organisation know not only how to respond internally, but when and how to escalate beyond its own environment?

At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.

Stay secure,
The Make Sense SRL Team & CyberTania