The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages of the attack, the agent modified personal data and accessed financial documents.
Although the Spanish agency has yet to investigate the incident and verify the information, the AEPD says the notification shows AI-related data breaches are no longer merely theoretical.
“The attacking agent began searching for vulnerabilities in generic files and successfully logged in,” describes AEPD.
“Once it gained access to the system, it began autonomously searching for vulnerabilities in the application. After finding them, it was able to modify personal data and access invoices.”
AEPD underlined that AI does not create new threats, but it can increase the speed, scale, and adaptability of cyberattacks, as well as reduce defenders' response-time margins, a paradigm shift recently highlighted by the country's National Cryptologic Center.
The notification signals a shift in risk management, which should explicitly account for AI-assisted and AI-driven attacks, as automation can affect an incident’s likelihood, speed, and scope.
Response time procedures should also be revised, since actions designed for manual attacks may be insufficient against agents that simultaneously analyze assets, test access methods, and adapt their behavior.
AEPD also highlights the importance of strengthening digital identity and credential security, because agents can use compromised accounts, API keys, or tokens with excessive permissions to access multiple services at machine speed.
Manual intervention is no longer sufficient, and human oversight should be supported by fast detection, containment, and response mechanisms.
... continue reading