Security News

Spain Reports First Data Breach Carried Out by an Autonomous AI Agent

The Register · 16 Sept 2026
Key Takeaway Small businesses should assume automated, AI-driven attacks can now move faster than manual response, so invest in monitoring tools, limit unnecessary data access, and keep vulnerability patching current.

Spain's data protection agency (AEPD) has reported the country's first known personal data breach caused by an autonomous AI agent. According to AEPD president Francisco Pérez Bes, an individual deployed an AI agent built on a well known large language model to attack an organisation. The agent scanned files, then ran vulnerability checks to find weaknesses that gave it read and write access to files containing personal data and invoices.

Pérez Bes said the attacker successfully chained together multiple stages of the attack using the agent, showing that AI-supported attacks are no longer just a theoretical risk. He called for organisations to adopt defence tools that can match the speed at which agentic attacks unfold, saying human oversight must be backed by fast detection, containment and response systems.

The incident comes as AEPD reports its busiest year yet for data protection complaints, with almost 31,000 received in 2025, a 64 percent rise on the previous year. Pérez Bes said the case should prompt an immediate review of security and data protection practices, with continued focus on understanding data processing activities, minimising data collection, limiting access, patching vulnerabilities, vetting suppliers and preparing incident response plans.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.