Skip to main content
Emerging ThreatsMalware & Ransomware

AI-Powered Agent Executes Multi-Stage Data Theft Attack in Spain

A dimly lit office with scattered papers and a computer terminal in the background.

"The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models," the AEPD concluded.

AEPD disclosure: Spain’s first agentic AI-powered personal data breach

On September 14, Francisco Pérez Bes, president of the Agencia Española de Protección de Datos (AEPD), announced what the agency described as Spain’s first "agentic AI-powered personal data breach." According to Pérez Bes's post, the incident involved an agent built on a "known language model" that initiated a scan of "generic files" and, through that activity, was able to "successfully log in" to a system. The AEPD said the agent then moved autonomously inside the environment, searching for vulnerabilities it could exploit.

How the attack unfolded, as reported

Pérez Bes laid out a short sequence: the agent scanned files, gained authenticated access, and "autonomously began searching for vulnerabilities in the application, which, once found, allowed them to modify personal data and access invoices." The AEPD also reported that the agent was used "as an instrument to successfully chain together different phases of the attack." The agency said little else publicly and stated that more detail will emerge only after it investigates the breach notification in greater depth.

What the AEPD says organizations must change now

Pérez Bes described the case as a watershed for Spain: AI has moved, in his words, "from a theoretical to a real-world risk." He urged organizations to update their risk approaches, arguing that "AI-assisted or driven attacks must be incorporated into data processing risk analyses, and acceptable response times should be reviewed." He also highlighted a renewed emphasis on credentials and response speed, saying the incident underscores "the growing importance of digital identities and credentials, and the need for machine-speed incident response."

Expert reaction — Simon Phillips, CybaVerse

Industry voices seized on the practical implications. Simon Phillips, CTO at CybaVerse, described the scenario as troubling because it suggests a human threat actor "managed to jailbreak or otherwise bypass the guardrails of an advanced model." Phillips urged clarity and urgency: “Hopefully we will understand more soon, because organizations need to know what they are facing with AI and where to invest their defenses,” he wrote. He added a broader critique: “There is currently too much hype around AI capabilities, and organizations are struggling to understand its impact on their environments. As an industry, we need to put an end to this.”

How technologists, policymakers, and affected enterprises are likely to respond

  • Technologists and security teams: Expect renewed focus on rapid detection and automated containment. The AEPD recommended preparing for "machine-speed incident response," and called for continuing fundamentals such as "understanding the processing activities" and "correcting vulnerabilities."
  • Policymakers and regulators: The AEPD framed the event as a shift in risk calculus for data protection, signaling that AI-driven threats should be part of formal risk analyses and that acceptable response times be revisited.
  • Affected enterprises and procurement leaders: The agency urged limiting access, minimizing data holdings, and "controlling suppliers" — practical steps aimed at reducing blast radius if an AI agent chains phases of an attack.

The AEPD concluded with a checklist of enduring controls even in an age of faster attacks: “Data protection officers, managers, and delegates must prepare for a scenario in which the speed of attacks will increase, but in which the same fundamentals will continue to be crucial: understanding the processing activities, minimizing data, limiting access, correcting vulnerabilities, controlling suppliers and being prepared to respond.”

For now, the basic facts are straightforward and the unknowns remain. The AEPD has signaled a formal investigation into the breach notification; until that review yields more detail, regulators, security teams and suppliers will be left to act on the AEPD’s public guidance and the stark implication that agentic AI can be used deliberately to chain multiple stages of a data-theft campaign.

Original story