SPAIN — An unnamed Spanish organization reported a personal data breach to Spain's Data Protection Agency (AEPD) in which an unidentified actor used an AI agent with human oversight to exploit loose credentials and a corporate application vulnerability. On Sept. 14, the AEPD described the breach report submitted by the organization, detailing how the attacker modified personal data records in the system and accessed corporate invoices.

The attacker used a "well-known language model" to breach corporate personal data stores after instructing the AI to search for vulnerabilities in generic files belonging to the victim organization. The AI agent discovered and exploited loose credentials and an enterprise application vulnerability, facilitating a successful login to an internal system using the discovered credentials.

After gaining access, the AI searched for vulnerabilities within the corporate application environment. This sequence of actions allowed the intruder to alter sensitive information and retrieve financial documents from the compromised network.

"What is relevant from a data protection perspective is that a third party would have used an AI agent as an instrument to successfully chain together different phases of the attack," the Spanish Data Protection Agency stated in its assessment of the incident.

In June, Spain's National Cryptologic Center (CCN) published a report warning about the cybersecurity risks of malicious AI. The government agency noted that "its impact lies not only in the emergence of new threats, but in the ability to accelerate, scale and automate known techniques, drastically reducing the time between identifying a vulnerability and exploiting it." "AI makes it possible to discover, chain together and exploit vulnerabilities in much shorter timeframes, limiting the ability of organizations to react," the CCN added in its June publication.

Aviv Nahum, co-founder and CEO at Above Security, said the speed of such attacks alters defensive strategies. "That changes the defender’s time horizon," he said. "Once an attacker or agent has valid credentials, a traditional control may simply see an authenticated user," Aviv Nahum said.

"The question becomes whether the behavior behind that identity still makes sense," Nahum said. "That is the same problem organizations already face with human insiders, except now the insider can be synthetic and operate continuously," he said.

"Security teams have traditionally assumed there is a human somewhere in the loop making decisions, pausing between steps and reacting to what happens," he said. He noted that this assumption no longer holds when automated agents are involved in the intrusion process.

"An agent can continuously investigate the environment, adapt and keep moving at machine speed," he said. This continuous operation removes the natural pauses that human attackers might take, allowing for persistent probing of systems.

"Incident response processes designed around human-paced attacks are going to struggle with that," he said. He argued that existing protocols may be insufficient for detecting and stopping threats that operate at digital speeds rather than human speeds.

Gene Moody, field chief technology officer at Action1, said the incident reflects a broader trend in cybersecurity. "The collision of 'It can!' and 'Should I?' makes this kind of incident look less like an anomaly and more like an early example of what will become a routine part of tomorrow's AI security reality," he said.

"I suspect incidents like this will soon stop being noteworthy because an AI agent was involved," Moody said. He predicted that the use of artificial intelligence in attacks will become standard practice for threat actors.

The AEPD recommended that organizations review and potentially speed up their incident response times. The agency also advised supporting manual intervention into data breaches with detection, containment, and response processes that work at machine speed.

Why It Matters

This breach shows the operational reality of AI-assisted cyberattacks, where known techniques are accelerated and scaled by automated agents. The involvement of a well-known language model and human oversight demonstrates how attackers can chain vulnerabilities together faster than traditional human-paced response processes can handle.

The event fits into a documented pattern of warnings issued by Spanish authorities, including the June report from the National Cryptologic Center on malicious AI risks. As defenders adjust to machine-speed threats, the distinction between human and synthetic insiders blurs, requiring new approaches to detection and containment that account for continuous, automated investigation of corporate environments.

What's New

Research titled "Spain ∙ GDPR ‘Glasnost’: The Spanish AEPD Raises the Transparency Bar and Sanctions Two Banks" was published in 2021 in European Data Protection Law Review. Simon Phillips is the CTO at CyberVerse.

"We don't have enough information to understand what happened or how the model carried out this breach," Phillips said. "We need to treat this incident with caution and avoid scaremongering the public with stories around AI once again running rogue." The AEPD Data Protection award is an Award conferred by the Spanish Data Protection Agency to experts on data protection. Investigation into the attack is continuing.

Timeline

June: Spain's National Cryptologic Center publishes a report warning about the cybersecurity risks of malicious AI. Sept. 14: The AEPD describes the breach report submitted by the unnamed Spanish organization.