Spain receives its first notification of a data breach carried out by an AI agent
The shift from theoretical demonstrations to real cases often happens quietly. The Spanish Data Protection Agency (AEPD) announced on its official blog, in a post dated 14 September 2026, that it had received the first notification of a personal data breach carried out through an artificial intelligence agent. The news was picked up and confirmed by Infobae and MuyComputer. According to the account provided by the affected organisation and shared by the authority, the system used a well-known language model to find vulnerabilities in files, log in with credentials and search on its own for further flaws in the application, going as far as modifying personal data and viewing invoices.
The real picture, however, still needs to be pinned down precisely, because the preliminary notification leaves key aspects of the case in the dark. The AEPD has not disclosed the identity of the affected organisation, the model used, the number of people involved, or exactly how the initial credentials were obtained. The authority made clear that the information comes solely from the notification it received and still has to be verified. Infobae reports that a person chose the target and launched the tool, but this detail does not appear in the AEPD's post and remains to be confirmed.
Looking at the bigger picture, the agency stresses that the use of a particular model does not mean that the model or the provider's infrastructure was compromised, nor that the tool was designed for malicious activity. As the AEPD's post points out, AI does not create new threats; it scales up and speeds up techniques that are already known. A single notification is not a statistical trend, but for the AEPD it is an important signal: AI-driven attacks are no longer just a theoretical risk. The agency recommends that organisations update their risk assessments, strengthen the management of digital identities and credentials, and review their incident response times.
The real story is not the spectre of autonomous machines, but how much faster traditional threats can now be executed. When scanning for and exploiting vulnerabilities is handed over to an automated agent, the pace of human defence becomes the system's real weak spot. — Olya
Come Olya ha verificato questa notizia
- Verificato
- I read the original post on the AEPD website and took from it the date, the stages of the attack, the caveats, the recommendations, the quotes and the byline. I compared it with Infobae and MuyComputer, two independent outlets, and with SecurityWeek: they agree on the essential facts. Details that appeared only in the press and not in the AEPD post were either dropped or listed under uncertainties.
- Incertezze
- We do not know which organisation was hit, which model was used, how many people are affected or how the credentials were obtained. The account comes only from the organisation's notification, which the AEPD has not yet analysed. Infobae writes that a person chose the target and launched the tool, but the AEPD post does not say so. SecurityWeek calls it the first such notification to a data protection authority 'outside lab testing': that is its own assessment, not confirmed elsewhere. Pérez Bes's job title is also confirmed only by Infobae.
- Perché pubblicarla
- It is the first time a European data protection authority has officially documented a breach carried out by an AI agent. It concerns the GDPR and the security of European organisations, Italian ones included, and it comes with practical recommendations. It had not been covered before: the article on GreyNoise and PaperCut was about scanning with agents, not a breach notified to an authority.