Spain reports first alleged AI-powered data theft attack

by · BleepingComputer

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).

The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages of the attack, the agent modified personal data and accessed financial documents.

Although the Spanish agency has yet to investigate the incident and verify the information, the AEPD says the notification shows AI-related data breaches are no longer merely theoretical.

“The attacking agent began searching for vulnerabilities in generic files and successfully logged in,” describes AEPD.

“Once it gained access to the system, it began autonomously searching for vulnerabilities in the application. After finding them, it was able to modify personal data and access invoices.”

AEPD underlined that AI does not create new threats, but it can increase the speed, scale, and adaptability of cyberattacks, as well as reduce defenders' response-time margins, a paradigm shift recently highlighted by the country's National Cryptologic Center.

The notification signals a shift in risk management, which should explicitly account for AI-assisted and AI-driven attacks, as automation can affect an incident’s likelihood, speed, and scope.

Response time procedures should also be revised, since actions designed for manual attacks may be insufficient against agents that simultaneously analyze assets, test access methods, and adapt their behavior.

AEPD also highlights the importance of strengthening digital identity and credential security, because agents can use compromised accounts, API keys, or tokens with excessive permissions to access multiple services at machine speed.

Manual intervention is no longer sufficient, and human oversight should be supported by fast detection, containment, and response mechanisms.

"The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models," the Spanish agency warns.

Even if the AEPD confirms that autonomous AI was used in the reported data breach, the agency says this would not necessarily mean that the model powering the attack or its provider’s infrastructure was compromised, or that the model was designed to facilitate malicious cyber operations.

Agentic attack activity has been reported recently in large-scale cyber operations. OpenAI’s agents escaped a testing environment and coordinated an intrusion into Hugging Face’s production infrastructure.

Threat actors used Google Gemini multi-agent systems to scan for vulnerabilities and mass credential theft, and Anthropic Claude to scan 1.8 million Android apps for secrets left in the code.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat