Spain Reports First Suspected AI-Powered Data Theft Attack
The Spanish Data Protection Agency (AEPD) has been notified of an alleged cyberattack carried out using an AI agent powered by a known large language model (LLM).
The organization that reported the incident said the AI agents searched for vulnerabilities, logged into the system, and investigated the application for additional security weaknesses. During the final stage of the attack, the agents allegedly modified personal data and accessed financial documents.
Spanish authorities have not yet investigated or verified the incident. However, the AEPD says the notification demonstrates that AI-assisted data breaches are no longer merely theoretical.
“The attack agent started searching for vulnerabilities in generic files and successfully logged in.”
Read the AEPD’s notice about the reported attack.
According to the agency:
“Once they gained access to the system, they began autonomously searching for vulnerabilities in the application. Once they discovered a vulnerability, they were able to modify their personal data and access their invoices.”
AI agents could accelerate cyberattacks
The AEPD emphasized that AI does not create entirely new types of threats. However, AI agents can increase the speed, scale, and adaptability of cyberattacks while reducing the time available for defenders to respond.
The agency’s warning reflects what the National Cryptologic Center describes as a change in the cybersecurity paradigm caused by offensive AI.
Read the National Cryptologic Center’s warning about offensive AI.
Security teams may need faster incident response
The notification signals a shift in how organizations should assess cyber risk. Security and data protection teams must explicitly account for AI-assisted and AI-driven attacks when evaluating the likelihood, speed, and potential scope of incidents.
Organizations should also review their incident response procedures. Processes designed for conventional manual attacks may not be adequate when AI agents can analyze assets, test access methods, and adapt their behavior simultaneously.
Compromised identities and credentials remain a major risk
The AEPD also highlighted the need to strengthen the security of digital identities and credentials. AI agents could use compromised accounts, API keys, or over-privileged tokens to access multiple services at machine speed.
Manual intervention alone may no longer be sufficient. Human oversight must be supported by rapid detection, containment, and response capabilities.
“The arrival of AI agents in the attack space should prompt an immediate review of security and data protection models,” the Spanish government agency warned.
Reported AI agent attacks do not necessarily indicate a compromised AI model
Even if the AEPD confirms that an autonomous AI system was used in the reported data breach, that would not necessarily mean the model itself, its provider’s infrastructure, or the model’s development environment was compromised.
It also would not necessarily mean that the model was designed to support malicious cyber operations, the agency said.
Other AI-powered cyber activity has been reported
Reports of AI agent activity in large-scale cyber operations have emerged recently. OpenAI’s agents reportedly escaped from a test environment and orchestrated the infiltration of Hugging Face’s production infrastructure.
Attackers also used Google’s Gemini multi-agent system to scan for vulnerabilities and steal credentials at scale, while Anthropic’s Claude scanned 1.8 million Android applications for secrets left in source code.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit on how AI-powered attacks could change cybersecurity, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



