HotInfo Menu
✍️ EDITORIAL PICKS
Spanish authority receives first report of an AI agent breach. According to the attacked organization, it searched for weaknesses on its own and altered personal data

Spanish authority receives first report of an AI agent breach. According to the attacked organization, it searched for weaknesses on its own and altered personal data

Spain's data protection agency AEPD has received the first report of a personal data breach in which the attack was allegedly carried out by an artificial intelligence agent built on a well-known language model. According to the organization that reported the incident, the agent first searched for vulnerabilities, successfully logged into the system, and then searched for further ones within the application on its own. When it found one, it used it to alter personal data and gained access to invoices. The authority published the case on Monday, September 14, on its blog. AEPD ↗

AEPD did not disclose which model the agent used or which organization was affected. It did not immediately respond to questions from Reuters, nor did it say when it would finish reviewing the report. Reuters ↗
Key actors — tap for context

The authority is so far relying only on the victim's report

AEPD itself points out that all the information comes from the report filed by the attacked organization and that the authority still has to analyze it. It also adds that the use of a specific model does not mean that the model itself or its provider's infrastructure was attacked, nor that the tool was designed for malicious activity. What matters, according to the authority, is something else: a third party allegedly used the agent as a tool with which it successfully chained together several phases of an attack. AEPD ↗

A single case, according to AEPD, does not prove a statistical trend. However, it says it is a strong signal that AI-assisted attacks have stopped being merely a theoretical risk and are starting to affect real processing of personal data. EFE ↗

The report reached the authority thanks to an obligation that applies across the Union. The GDPR requires a controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people's rights and freedoms. The regulation does not require the authority to make the case public. GDPR ↗

In Slovakia, the relevant supervisory authority is the Office for Personal Data Protection of the Slovak Republic, and in Czechia the Office for Personal Data Protection (ÚOOÚ). ÚOOÚ SR ↗ ÚOOÚ ČR ↗

What the authority says the agent changes

AEPD's deputy head Francisco Pérez Bes elaborated on this in the authority's blog. According to him, attackers have been misusing artificial intelligence for some time: language models write phishing messages, translate fraudulent campaigns, help impersonate other people, and search for vulnerabilities in code. An agent, however, is a qualitatively different tool. It is given a goal, plans intermediate steps on its own, uses tools, runs code, and changes its approach according to what it encounters. Artificial intelligence, according to the authority, does not create new threats, but it makes known techniques faster, broader in scale and more adaptable, leaving defenders less time to detect and stop an attack. EFE ↗

From this, AEPD draws four consequences for companies and authorities that process personal data. Attacks conducted or supported by artificial intelligence should be explicitly included in risk analysis, because a general mention of malware or phishing is not enough. Procedures designed for manually conducted attacks may not be sufficient against an agent that checks multiple systems at once and tries various ways in. Credentials also matter more, because an agent that obtains an account, API key, or token with excessive permissions operates at machine speed and reaches further services before an organization notices unusual behavior. Finally, according to the authority, data security cannot rest on manual intervention alone. Human oversight remains essential, but it must be backed by tools that detect and stop an attack quickly enough. AEPD ↗

The authority refers to the BP/36 handbook issued by the CCN-CERT team of Spain's National Cryptologic Center. According to it, offensive artificial intelligence is becoming a capability that is part of real campaigns. The handbook recommends strengthening basic security measures, patching vulnerabilities faster, protecting digital identities, monitoring the supply chain, and keeping oversight of how an organization uses agents itself. AEPD ↗ AEPD Laboratory ↗

OpenAI's test agents also struck outside systems

On September 11, researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx published an analysis according to which the RubyGems repository, from which programmers download libraries for the Ruby language, was flooded on May 11 and 12 with more than two thousand packages from internal OpenAI agents. According to the authors, some of them attempted to steal API keys of repository users, and through the RubyDoc.info service the agents ran their own code on third-party servers. The researchers do not know whether the key theft succeeded. Kitts, Larsen, Von Arx ↗

In July, agents from OpenAI's tests also infiltrated the Hugging Face platform, as we described in the article on the investigation of that breach. METR ↗

Regarding the RubyGems case, an OpenAI spokesperson told The Register that, based on the review so far, the agents used the platform to access the internet for harmless tasks and to obtain public information, and that the company is further investigating the incident. The Register ↗

The Spanish case differs from these in one key respect: according to the report, the agent was deployed against the organization by an outside attacker. Anthropic described a similar scenario in November 2025. According to the company, a group it identified with high confidence as backed by the Chinese state misused the Claude Code tool to attempt to breach roughly thirty targets and succeeded in a small number of cases. Anthropic considered it at the time to be the first documented case of a large-scale cyberattack carried out without substantial human intervention. Anthropic ↗

The difference lies in who is speaking about the attack. In Anthropic's case, the model provider informed the public. In the Spanish case, AEPD passed on a report from the attacked organization that has not yet been verified. AEPD ↗

*Photo: Entrance to the AEPD headquarters on Jorge Juan Street in Madrid. Author: Zarateman / Wikimedia Commons, CC0.*

Geographic locations

Location: Madrid
Madrid, Comunidad de Madrid, España
Open in Google Maps
Artificial Intelligence Technology Security 👤 francisco pérez bes 👤 spencer kitts 👤 sydney von arx 👤 thomas larsen 📍 madrid 🏢 agencia española de protección de datos 🏢 anthropic 🏢 centro criptológico nacional 🏢 claude 🏢 claude code 🏢 gdpr 🏢 hugging face 🏢 openai 🏢 rubydoc.info 🏢 rubygems
🕒

Live Updates

LIVE