THE Spanish Data Protection Agency (AEPD) has published details of what it describes as the first notification of a personal data breach carried out through an AI agent. The investigation is ongoing, and the agency has not publicly established exactly how the attack was conducted. According to the AEPD, an attacker successfully logged in, searched for vulnerabilities, modified personal data and accessed invoices.
The notable feature was the use of an AI agent to link multiple stages of the intrusion: receiving a goal, planning tasks, using tools, executing code, consulting information and adapting its actions autonomously.
The incident suggests that organisations should include adversarial AI agents in risk assessments, improve response times and strengthen the protection of digital identities and credentials. The AEPD said human supervision remains essential, but must be backed by detection, containment and response systems capable of operating quickly rather than relying solely on manual intervention.
CyberVerse CTO Simon Phillips urged caution, saying there is not enough information to determine how the model contributed to the breach. He identified several possible explanations, including an attacker bypassing model safeguards through a jailbreak, an AI system escaping a poorly configured testing environment, or an unauthorised penetration test using a model based on a popular large language model. None of these scenarios has been confirmed, and the AEPD’s investigation continues.