Spain Receives First Reported Data Breach Carried Out by AI Agent
Spain's Data Protection Agency (AEPD) receives its first notification of a data breach allegedly carried out by an AI agent powered by a known large language model. The reporting organization says the agent searches for flaws, logs into systems, probes applications for additional vulnerabilities, and ultimately modifies personal data and accesses invoices. While the AEPD has yet to investigate and verify the incident, the agency says the notification shows AI-related data breaches are no longer purely theoretical.
The AEPD emphasizes that AI does not create entirely new threats, but it increases the speed, scale, and adaptability of cyberattacks while shrinking defenders' response-time margins. The agency calls for a shift in risk management that explicitly accounts for AI-assisted and AI-driven attacks, since automation affects an incident's likelihood, speed, and scope. Response procedures designed for manual attacks may prove insufficient against agents that simultaneously analyze assets, test access methods, and adapt their behavior.
The agency also urges organizations to strengthen digital identity and credential security, noting that AI agents can exploit compromised accounts, API keys, or over-privileged tokens to access multiple services at machine speed. Manual intervention alone is no longer enough, and human oversight must be supported by rapid detection, containment, and response mechanisms. The AEPD cautions that even if autonomous AI use is confirmed, it would not necessarily mean the model itself or its provider's infrastructure was compromised or designed for malicious operations.