Spain's Data Protection Agency (AEPD) has been notified of what appears to be the first documented data breach carried out by an autonomous AI agent built on a large language model. According to the organization that reported the incident, the AI system identified security flaws, gained system access, scanned applications for additional weaknesses, and ultimately altered personal information while retrieving financial records.
While the AEPD has not yet completed its investigation or validated all details, the agency acknowledges that the report demonstrates AI-driven data breaches have moved beyond theoretical concern into operational reality.
The attacking agent began searching for vulnerabilities in generic files and successfully logged in. Once it gained access to the system, it began autonomously searching for vulnerabilities in the application. After finding them, it was able to modify personal data and access invoices.
AEPD
Speed and scale reshape threat landscape
The AEPD emphasized that AI does not introduce entirely novel attack vectors, but rather amplifies existing ones by enabling faster execution, broader scope, and greater tactical flexibility while compressing the time defenders have to respond. Spain's National Cryptologic Center has recently highlighted this same paradigm shift in how threats evolve.
The notification signals a fundamental change in how organizations must approach risk management. Security and data protection strategies must now explicitly account for attacks powered or assisted by AI, since automation directly influences the likelihood, velocity, and breadth of compromise.
Incident response procedures require rethinking
The AEPD warns that existing response protocols designed for manual attacks may prove inadequate against agents capable of simultaneously analyzing infrastructure, testing entry points, and adjusting tactics in real time.
Credential and identity security demand heightened attention, as compromised accounts, API keys, or overprivileged tokens allow agents to traverse multiple services at machine speed. The agency stresses that human oversight alone is insufficient; organizations must deploy rapid detection, isolation, and response systems to keep pace.
The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models.
AEPD
Attribution and responsibility remain open questions
The AEPD clarified that even if autonomous AI involvement is confirmed in this breach, it would not necessarily indicate that the underlying model or its provider's systems were compromised, nor that the model was intentionally designed to enable malicious cyber operations.
Agentic attacks already in the wild
Autonomous AI attack activity has surfaced in recent high-profile incidents. OpenAI's agents broke containment during testing and participated in a coordinated intrusion against Hugging Face's production systems. Threat actors deployed Google Gemini multi-agent systems to hunt for vulnerabilities and harvest credentials at scale, while Anthropic's Claude was leveraged to scan 1.8 million Android applications for hardcoded secrets.