AI & Emerging Tech

Spain’s Data Regulator Logs First Breach Blamed on an Autonomous AI Agent

Spain’s Data Regulator Logs First Breach Blamed on an Autonomous AI Agent

The Spanish Data Protection Agency has received its first breach notification in which the reporting organisation says the attack was executed by an autonomous AI agent. According to the AEPD, the agent searched generic files for weaknesses, logged in successfully, then worked through the application on its own until it could alter personal data and open invoices. The agency published the account on 14 September 2026 and has not yet verified it.

Francisco Pérez Bes wrote up the notification for the AEPD’s blog and he is precise about what the agency actually knows. The information comes from the affected organisation and still has to be analysed. The involvement of a particular AI model does not mean that model or its provider’s infrastructure was compromised, nor that the tool was built to run malicious operations.

The Only Witness Is the Victim

Everything known about this incident comes from the organisation that was breached. The AEPD says so in the second paragraph of its own post. Hold on to that because “an autonomous AI agent did this” is a considerably more comfortable sentence for a breached company than “someone obtained our credentials and walked through an application we had not patched.” Until the agency finishes its analysis, read the agentic framing as the victim’s account rather than a regulatory finding.

One detail in the AEPD’s own description deserves a second look. The agent searched generic files for vulnerabilities and then it logged in successfully. The login came before the application was probed. Whatever ran this attack, it started with working credentials.

What Changes When the Attacker Plans Its Own Next Step

AI in offensive operations is not new. Generative models have been drafting phishing messages, translating fraud campaigns, impersonating people and reading code for years. The AEPD’s argument is narrower than the headline suggests, an agent can take an objective, plan the intermediate tasks, use tools, execute code, consult sources, interpret what comes back and change its behaviour on its own without an operator approving each step.

The agency’s formulation is the one worth repeating. AI does not create new threats. It raises the speed, scale and adaptability of techniques that already worked and it cuts the time defenders have to spot them and shut them down.

Spain’s Cryptologic Centre Got There First

The AEPD points readers to CCN-CERT BP/36, the good practice guide on offensive AI published by the Centro Criptológico Nacional. The CCN’s position is that offensive AI has become an operational capability inside live campaigns rather than a research topic. Its recommendations are conventional and none the worse for it, reinforce essential controls, accelerate vulnerability management, protect identities, control the supply chain and govern how agents are used inside the organisation.

OpenAI agents escaped a testing environment and coordinated an intrusion into Hugging Face’s production infrastructure. Threat actors ran Google Gemini multi-agent systems for vulnerability scanning and mass credential theft. Anthropic’s Claude was abused to scan 1.8 million Android apps for secrets left in code. In none of those cases was the model provider itself breached.

Credentials and Tokens Are the Actual Exposure

The AEPD’s risk management conclusions read as a checklist. A risk analysis that gestures at malware, phishing and unauthorised access in generic terms no longer covers the ground. The agency says automation substantially changes the probability, speed and scope of an incident and that risk assessments now have to name AI-assisted and AI-executed attacks explicitly.

The identity point is the sharpest one in the post. An agent that obtains an account, an API key or a token carrying more permissions than its job requires can move between services at machine speed long before anyone reviews the logs. That is a permissions problem and it predates agentic AI by about two decades.

The 72-Hour Clock Does Not Care How Fast the Attack Was

For Swedish organisations the obligation is unchanged. Article 33 of the GDPR still requires notification to Integritetsskyddsmyndigheten within 72 hours of becoming aware of a personal data breach regardless of what executed it. The Spanish case is a preview of the paperwork: a controller describing an attack it did not fully observe, to a supervisory authority that will want to know how the initial access was obtained.

Audit service accounts, API keys and tokens for permissions nobody has reviewed this year and cut the ones that exceed their purpose. Then time your own detection. If an attacker chained reconnaissance, login, application exploitation and data modification inside a single session, how long would your team take to see it? The AEPD’s closing advice to controllers, processors and data protection officers comes down to six things that predate AI entirely: know your processing, minimise the data, limit access, fix vulnerabilities, control your suppliers and be ready to respond.

References

  1. Primera Notificación De Una Brecha De Datos Personales Causada Por Un Ataque Ejecutado Mediante Un Agente De IA (AEPD)
  2. Spain’s Data Agency Gets First Report of AI-powered Data Breach
  3. El Centro Criptológico Nacional Alerta Del Cambio De Paradigma Que Supone La IA Ofensiva Para La Ciberseguridad
  4. Nearly 700 Rogue AI Agents Coordinated in the Hugging Face Attack
  5. Hackers Build AI Frameworks for Widescale Credential Theft
  6. Hackers Abused Claude to Extract Secrets From 1.8M Android Apps

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.