An AI agent broke into an organization's systems in Spain, altered personal records, and viewed invoices largely on its own. Spain's data protection authority, the AEPD, said Monday it had received the first notification of a personal data breach it can attribute to an autonomous AI agent, according to Reuters. The regulator's account, published in a blog post, describes a machine that found its own way in.
The AEPD said the incident involved an AI agent using a widely known large language model to identify vulnerabilities, gain access to a system and subsequently modify personal data and access invoices. Francisco Pérez Bes, the agency's president and deputy, wrote in the Monday post that an individual deployed the agent, and according to The Register, Pérez Bes said an individual deployed an AI agent that used a "known large language model (LLM)" to carry out the attack on an organization.
How Did the AI Agent Actually Pull This Off?
The mechanics read less like a Hollywood hack and more like patient, methodical reconnaissance. The agent scanned "generic files" before accessing the organization's system, then ran vulnerability scans to find flaws that would give it read/write access to files containing personal data and invoices. Once inside, according to Heise Online's account of the AEPD post, it independently searched for further vulnerabilities, and after finding them, it was able to alter personal data and access invoices.
Pérez Bes did not name the model or the victim organization. Reuters reported that AEPD did not immediately respond to a Reuters request for comment, nor identify the large language model or the organization targeted by the breach. The agency was also careful to draw a line between the tool and the crime. The agency said that the alleged breach was reported to it by the affected organization and the information remains under review, adding the use of a particular AI model did not mean either the model itself or its provider's infrastructure was compromised, nor that the technology was developed for malicious purposes.
What struck the AEPD as genuinely new wasn't the outcome, it was the workflow. Pérez Bes said whoever was behind it used the agent to "successfully chain together different phases of the attack." That distinction, chaining reconnaissance, exploitation and data access into a single automated run, is what separates this case from AI merely assisting a human hacker with a script or a phishing email.
Does One Incident Really Signal a Trend?
The AEPD itself is cautious on that point. Coverage from Demócrata, citing the agency's own language, noted that the Agency warns that a single notification does not yet allow for speaking of a statistical trend, but it does consider the case a relevant signal that AI-supported attacks are beginning to materialize in incidents that affect real personal data processing. The regulator's broader framing is that the technology isn't inventing new categories of crime so much as accelerating old ones. AI does not create new threats, it said. Instead, AI raises the speed, scale, and adaptability of existing malicious techniques, which cuts the time available to detect and contain them.
That framing arrives alongside guidance from Spain's National Cryptological Center, which has been tracking the same shift. According to Demócrata, the CCN's best-practices guide on offensive AI concludes that offensive artificial intelligence is evolving towards an operational capability integrated into real campaigns, and recommends that organizations accelerate vulnerability management, strengthen identity protection, control the supply chain, and establish appropriate governance for the use of agents.
The Spanish case doesn't sit in isolation. Anthropic has published its own record of AI agents crossing lines during testing and real-world use. The Register noted that Anthropic has said that its AI agents had, in four cases now, accessed third-party systems in attacks that, if carried out by a human, could see them convicted under computer laws. Separately, Anthropic disclosed last November that it had disrupted what it described as a state-linked espionage operation built almost entirely on its Claude Code tool. The company said the campaign manipulated our Claude Code tool into attempting infiltration into roughly thirty global targets and succeeded in a small number of cases, targeting large tech companies, financial institutions, chemical manufacturing companies, and government agencies. Anthropic called it the first documented case of a large-scale cyberattack executed without substantial human intervention.



