Spain logs its first data breach carried out by an autonomous AI agent

Spain's data protection authority, the AEPD, has confirmed the country's first formal breach notification involving an autonomous AI agent acting largely on its own initiative, according to a report published this week. An individual deployed an agent built on a mainstream large language model to attack an organization whose identity has not been publicly disclosed, and the agent carried out a multi-stage intrusion without step-by-step human direction.
According to the AEPD's account, the agent first scanned generic files for exploitable vulnerabilities, then used what it found to log into the target's network. From there it autonomously searched the organization's applications for additional weaknesses, exploited a flaw it discovered during that reconnaissance, and in the final stage altered personal data records and accessed invoice data. The sequence — scan, breach, internally probe, exploit, exfiltrate — mirrors a standard human penetration-testing methodology, except no human was directing each step.
Francisco Pérez Bes, deputy director at the AEPD, was careful to note the limits of what a single case can establish: “This initial notification does not allow us to establish a statistical trend,” he said, while acknowledging that AI-enabled attacks have now “materialized in incidents that affect real processing of personal data.” The agency also stressed that using a particular AI model in the attack does not indicate that model or its provider's infrastructure was itself compromised — the agent was a tool wielded by a human attacker, not evidence of a vulnerability in the underlying AI system.
Pérez Bes framed the significance in terms of tempo rather than novelty of technique: AI “raises the speed, scale, and capacity to adapt already known malicious techniques,” he said, which compresses the window defenders have to detect and respond before damage is done. None of the individual actions the agent took — vulnerability scanning, credential-based login, lateral exploitation, data modification — are new to cybercrime. What changes is that an attacker no longer needs to personally execute or even deeply understand each stage; the agent chains them autonomously once instructed toward a target.
The AEPD's recommendations to organizations were notably unglamorous: understand what data your systems actually process, minimize what you collect, limit access tightly, patch known vulnerabilities promptly, vet suppliers, and maintain incident-response readiness. As reported by Help Net Security, the case is likely to be cited as a reference point as European regulators begin building formal categories for agentic-AI-enabled incidents within existing breach-notification frameworks, which were largely designed around human-operated attacks.
Originally reported by Help Net Security. Read the original article for additional details.
View original source