Spanish privacy agency announces inaugural security violation driven by autonomous algorithm

The Spanish flag outside Madrid City Hall. Credit: MSCT / Shutterstock “The arrival of AI agents in offensive activity must drive an immediate review of security and data protection models,” wrote Francisco Pérez Bes of Spain’s data protection agency, the AEPD. The AEPD has received its first notification of a personal data breach carried out with an AI agent. Pérez Bes announced it in an agency blog post on 14 September, in Spanish.

The agent used a well-known large language model, he wrote. The Register first reported the case in English. What the agent did According to the AEPD, the agent began by searching generic files for vulnerabilities and then logged in successfully. Once inside, it searched the application for flaws on its own.

When it found one, it could modify personal data and access invoices. The agency did not name the model or the organisation. Pérez Bes wrote that the details come from the organisation’s own notification, and the AEPD still has to analyse them. He added that the use of a particular model does not mean anyone compromised the model or its provider’s systems.

It also does not mean the provider built the tool for malicious use. For data protection, he wrote, the key point is that a third party used an agent to chain together different phases of the attack. One notification does not show a trend, according to the post. It does show that AI-supported attacks are no longer only a theoretical risk.

What the AEPD wants organisations to change Pérez Bes set out four consequences for organisations that handle personal data. First, risk analyses should explicitly cover attacks that use AI. A generic reference to malware, phishing or unauthorised access is not enough. Second, organisations should review their response times.

Procedures built for manual attacks may be too slow for an agent that tests several assets at once. Third, digital identities and credentials matter more. An agent with an account, API key or token that has too many permissions can move between services at machine speed. Fourth, security cannot depend on manual work alone.

Human oversight stays essential, he wrote, but it needs fast detection, containment and response behind it. The post also cites a guide from Spain’s National Cryptologic Centre, CCN-CERT BP/36. The guide warns that attackers now use offensive AI in real campaigns. The AEPD received 30,931 complaints in 2025, according to its annual report, as cited by The Register.

That was the most in its history. It was also 64% more than the year before. The Register said it had asked the AEPD for more details. Agents in earlier incidents Earlier cases involved AI labs’ own models in testing.

In July, OpenAI said agents under evaluation had compromised parts of Hugging Face. Researchers later found the agents had probed the site in May. Anthropic has disclosed cybersecurity incidents with its models in testing. A separate Anthropic report showed how outside actors misused Claude.

In Europe, the EU cybersecurity agency ENISA used an OpenAI model to find four flaws in EU code. OWASP’s 2026 list of LLM application risks includes excessive agent permissions.

Leave a Reply

Your email address will not be published. Required fields are marked *