Spain Reports First AI Agent Data Breach
Spain's data protection agency has disclosed the country's first confirmed personal data breach carried out by an agentic AI.

Spain's data protection authority, the Agencia Espanola Proteccion Datos (AEPD), has reported the nation's first personal data breach executed by an agentic artificial intelligence. AEPD president Francisco Pérez Bes revealed the incident in a statement on September 14.
According to Pérez Bes, an agent using a "known language model" initiated the attack by scanning generic files, which enabled it to successfully log into a target system. The agency stated that, once inside, the AI autonomously searched for application vulnerabilities. Upon finding them, it modified personal data and accessed invoices.
The AEPD indicated that the AI was used "as an instrument to successfully chain together different phases of the attack." This implies proactive use by a threat actor, rather than a rogue AI system. Simon Phillips, CTO at CybaVerse, argued this scenario is troubling as it suggests a threat actor managed to jailbreak or otherwise bypass the guardrails of an advanced AI model. "Hopefully we will understand more soon, because organizations need to know what they are facing with AI and where to invest their defenses," he said.
A Watershed for AI Threats
Pérez Bes described the case as a watershed moment. He argued that AI-assisted or driven attacks must now be incorporated into organizational data processing risk analyses. Also, he stated that acceptable incident response times need to be reviewed in light of machine-speed attacks.
The incident also highlights the growing critical importance of securing digital identities and credentials. The AEPD concluded that the arrival of AI agents in offensive cyber operations should prompt an immediate review of existing security and data protection models.
Fundamentals and Response
Despite the new threat vector, the AEPD emphasized that core security principles remain vital. Data protection officers and security managers must prepare for accelerated attack speeds while relying on established fundamentals. These include thoroughly understanding data processing activities, minimizing data collection, limiting access rights, promptly correcting unpatched vulnerabilities, controlling suppliers, and maintaining strong incident response preparedness.
The AEPD stated that little more is known about the specific incident until it investigates the breach notification in more detail.





