The Spanish data protection agency, the AEPD, has received its first notification of a personal data breach carried out with an AI agent. According to the agency, the agent began by searching generic files for vulnerabilities and then logged in successfully. Once inside, it searched the application for flaws on its own and was able to modify personal data and access invoices.

The agency did not name the model or the organization involved, but noted that the details came from the organization's own notification. The AEPD still has to analyze the details, but the incident highlights the growing risk of AI-supported attacks.

Francisco Pérez Bes, of the AEPD, wrote in a blog post that the use of a particular model does not mean anyone compromised the model or its provider's systems. It also does not mean the provider built the tool for malicious use. However, the key point is that a third party used an agent to chain together different phases of the attack.

Pérez Bes set out four consequences for organizations that handle personal data. First, risk analyses should explicitly cover attacks that use AI. A generic reference to malware, phishing, or unauthorized access is not enough. Second, organizations should review their response times, as procedures built for manual attacks may be too slow for an agent that tests several assets at once.

Third, digital identities and credentials matter more, as an agent with an account, API key, or token that has too many permissions can move between services at machine speed. Fourth, security cannot depend on manual work alone, and human oversight needs fast detection, containment, and response behind it.

The AEPD received 30,931 complaints in 2025, the most in its history, and 64% more than the year before. This incident highlights the need for organizations to review their security and data protection models in response to the growing risk of AI-supported attacks.

Earlier cases involved AI labs' own models in testing, but this incident shows that AI-supported attacks are no longer just theoretical. The EU cybersecurity agency ENISA has used an OpenAI model to find flaws in EU code, and OWASP's 2026 list of LLM application risks includes excessive agent permissions.

Este artículo fue escrito con la asistencia de IA.
News Factory APP - noticias agénticas para impulsar tu SEO y AEO.