SPAIN’S data protection authority, the AEPD, has reported what it described as a personal data breach caused by an attack conducted through an AI agent. The unnamed organisation submitted the report, published by the AEPD on 14 September 2026. According to the limited details available, an unidentified hacker used a “well-known language model” to search generic files belonging to the organisation, uncover credentials and exploit a vulnerability in an enterprise application.
The attacker then gained access to personal data records, modified them and viewed corporate invoices. The AEPD has not identified the organisation, the attacker or the language model, and the report does not establish that the system operated without human oversight.
The incident illustrates how AI may accelerate and link conventional attack steps, including reconnaissance, credential use and exploitation, rather than relying on a wholly new type of vulnerability. Spain’s National Cryptologic Center warned in June that offensive AI could reduce the time between finding and exploiting weaknesses.
Security experts quoted by Dark Reading said machine-speed activity may challenge response processes built around slower, human-led attacks, particularly when valid credentials make malicious activity appear authenticated. The AEPD highlighted the need to protect identities and credentials, review whether incident-response processes can operate quickly enough, and combine human intervention with detection, containment and response capabilities able to function at machine speed.