First Agentic AI Data Breach Reported to Spanish Regulator

https://www.securityweek.com/wp-content/uploads/2026/07/AI-artificial-intelligence-model-frontier.webp

The Spanish Data Protection Agency (AEPD) has published details of the first notification of a personal data protection breach executed by design through an AI agent.

Investigation into the attack is continuing, and the AEPD uses its words carefully. Nevertheless, although AI-assisted attacks have become common (deepfakes, authoring phishing emails, scaling attacks through automation, etcetera), this appears to be the first known agentic attack outside of a rogue frontier model agent. Bad actor agents are moving beyond a theoretical probability into the real world.

The attack itself involved a successful login, followed by a search for vulnerabilities, and the ability to modify personal data and access invoices. “What is relevant from a data protection perspective,” writes AEPD, “is that a third party would have used an AI agent as an instrument to successfully chain together different phases of the attack.”

This, suggests the agency, is a qualitative change. “An agent...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more