Spain’s data protection regulator has received its first notification of a personal-data breach reportedly executed using an AI agent. The affected organization described a sequence in which the agent logged into a system, searched for application vulnerabilities and obtained the ability to modify personal data and access invoices.

The Spanish Data Protection Agency, known as AEPD, disclosed the notification in a September 14 blog post. It cautioned that the account comes from the organization’s notification and must undergo analysis before the agency reaches conclusions. The first refers to notifications received by AEPD, rather than a verified first attack worldwide.

The notification describes an agent using a well-known language model. AEPD said use of a model does not establish that the model or its provider’s infrastructure was compromised, or that the tool was designed for malicious activity. It also cautioned that a single notification cannot establish a statistical trend.

The agency called for organizations to explicitly include AI-assisted attacks in assessments of personal-data processing risks. Its guidance emphasizes reviewing response times and controlling accounts, API keys and tokens with excessive permissions, alongside detection and containment systems fast enough to support human supervision.

AEPD cited the National Cryptologic Centre’s guide to offensive AI, published in June. The centre, part of Spain’s National Intelligence Centre, describes AI as multiplying the speed, scale and autonomy of established attack techniques, including phishing, malicious-code generation, vulnerability exploitation and reconnaissance.

That guide recommends identity management, network segmentation, continuous monitoring and access controls. It also addresses operational technology, where essential services, sensitive information and connections between organizations and suppliers can increase exposure. The centre recommends secure-by-default systems and defensive AI subject to human oversight, traceability and clear limits on its actions.

Its proposed implementation roadmap begins with closing basic security gaps, then redesigning processes to respond at the speed of automated threats. Later stages involve governed defensive agents and specialist testing teams. The recommendations concern organizational preparedness, rather than findings about the newly notified breach.

Google has separately documented a multi-agent credential-harvesting operation that compromised thousands of third-party credentials in less than six hours after an attacker obtained cloud access. Its report distinguishes automated scanning and collection from a fully autonomous attack pipeline, which Google said it had not observed in the wild at the time.

Rubrik is also accepting selected partners for a Claude Mythos 5 code red-teaming preview that tests vulnerability chains in isolated repository copies. Rubrik targets general availability for fall 2026.

Sources: AEPD, CCN


By the Control Plane Editorial Team