Spain receives first alleged report of AI agent data breach
Spain’s data protection agency says it has received the country’s first breach notification alleging that an autonomous AI agent carried out multiple stages of a cyberattack with limited human intervention. According to the affected organization’s report, the agent used a widely known large language model to scan files, identify vulnerabilities, access a system, alter personal data and view invoices. The AEPD has not identified the model or organization and stressed that the incident does not indicate that the model or its provider’s infrastructure was compromised or designed for malicious use. The agency said the case shows AI-assisted attacks are moving beyond theory by accelerating existing attack methods, leaving organizations less time to detect and contain them. It urged companies to review security and data-protection practices while maintaining human oversight and stronger controls over access, vulnerabilities and data processing.





