VECTOR WIREAI INTELLIGENCE
UTC
Refresh Models Deals Regulatory Sources

Spain logs first data breach carried out by an autonomous AI agent

Spain's AEPD registered its first personal data breach allegedly executed by an autonomous AI agent that chained multiple attack stages with limited…

Spain's data protection authority has registered the first personal data breach on its books in which an AI agent allegedly executed a multi-stage cyberattack with limited human intervention, marking what the regulator calls a concrete signal that AI-driven intrusions are beginning to hit real systems.

The Spanish Data Protection Agency (AEPD) said on September 15 in a blog post that the incident involved an AI agent using a widely known large language model to identify vulnerabilities, gain access to a system, modify personal data, and access invoices3,5. The breach was reported to the AEPD by the affected organization, and the information remains under review.

How the attack unfolded

According to the notification, the agent began by searching for vulnerabilities in generic files and successfully logged into the target system1. Once inside, it autonomously probed the application for additional weaknesses. After identifying an exploitable flaw, it altered personal information and viewed billing records.

The AEPD said the case stood out because a third party allegedly used an AI agent to chain together different phases of a cyberattack rather than limiting AI to assisting a human operator on specific tasks. The agency cautioned that a single notification does not constitute a statistical trend but called the incident a relevant signal that AI-supported attacks are materializing in incidents affecting real personal data.

Regulator caveats and broader warnings

The AEPD did not identify the large language model involved or the targeted organization. It stressed that the use of a particular model does not mean the model itself or its provider's infrastructure was compromised, nor that the technology was designed for malicious purposes. The agency also noted that the details come solely from the affected organization's notification and still require its own analysis.

Beyond the specific incident, the AEPD said AI does not create fundamentally new threats but increases the speed, scale, and adaptability of existing attack techniques, reducing the time organizations have to detect and contain intrusions. It warned that procedures designed to address manually developed attacks may be insufficient when an agent can simultaneously analyze different assets, test multiple entry points, and modify its behavior at machine speed. If an agent gains access to an account, API key, or token with excessive permissions, it can move between services before anomalous behavior is flagged.

The agency said controllers, processors, and data protection officers must prepare for a scenario in which attack speed continues to increase, and that organizations should rethink their risk analyses to expressly incorporate AI-assisted or AI-executed attacks. It concluded that data protection can no longer rely exclusively on manual intervention and that human supervision must be complemented with detection, containment, and response systems fast enough to handle automated AI attacks.

The AEPD's warning aligns with guidance from Spain's National Cryptological Center (CCN), which considers offensive AI to be evolving toward an operational capability integrated into real campaigns and recommends accelerating vulnerability management, strengthening identity protection, controlling the supply chain, and establishing governance for the use of agents.

ANALYSIS The AEPD's filing is notable less for the breach itself, whose details remain unverified, than for the regulatory posture it establishes: a European data authority treating an autonomous AI agent as the attacker of record, rather than merely a tool in a human-led operation.