A Spanish organization has suffered a personal data breach at the hands of an agentic AI system (with human oversight).
On Sept. 14, Spain’s Data Protection Agency (AEPD) — the Spanish government’s data protection watchdog — described a breach report submitted by an unnamed organization, in which an unidentified hacker used a “well-known language model” to breach corporate personal data stores. Details are scarce, but the AI appears to have discovered and exploited a set of loose credentials, plus an enterprise application vulnerability, allowing its proprietor to modify personal data records and access corporate invoices.
Dark Reading contacted the AEPD for further details on this story, and will update this article should the agency provide any.
Profile of an Agentic Data Breach
In June, Spain’s National Cryptologic Center (CCN) published a report warning about the “paradigm shift” malicious AI represents for cybersecurity. “Its impact lies not only in the emergence of new threats, but in the ability to accelerate, scale and automate known techniques, drastically reducing the time between identifying a vulnerability and exploiting it,” the agency wrote (machine-translated by Dark Reading).
It was never going to take long for this prediction to become reality in Spain itself. According to AEPD, an unidentified human puppeteer recently used AI to accelerate, automate, and likely reduce the time it would’ve otherwise taken them to identify a vulnerability in a corporate application, and exploit it to reach personal data.
As CCN noted in its report, “By combining open-source intelligence with direct reconnaissance capabilities against infrastructure, attackers can precisely map digital assets such as websites, programming interfaces, cloud services or infrastructure-as-a-service environments.” Indeed, the attacker first instructed their AI to search for vulnerabilities in “generic” files belonging to a victim organization, according to AEPD. That activity turned up corporate credentials, evidently, as the AI was then able to facilitate a successful login to an internal system.
“AI makes it possible to discover, chain together and exploit vulnerabilities in much shorter timeframes, limiting the ability of organizations to react,” CCN warned in the spring. “Just the same, once inside of the particular corporate application their login afforded access to, our enterprising attacker’s AI searched for vulnerabilities in that application’s environment. This worked, allowing its human owner to modify personal data in the system and access invoices.”
Are Agentic Attacks Already Old News?
Stories of AI-driven cyberattacks might leave one feeling less shocked today than they did earlier in 2026. Gene Moody, field chief technology officer (CTO) at Action1, notes how obvious it is that AI already has the capability, and that hackers en masse are inevitably starting to take advantage.
“The collision of ‘It can!’ and ‘Should I?’ makes this kind of incident look less like an anomaly and more like an early example of what will become a routine part of tomorrow’s AI security reality,” he argues.
In this new reality, where autonomous systems can chain familiar cyberattack steps together without a human manually driving every stage, “That changes the defender’s time horizon,” says Aviv Nahum, co-founder and CEO at Above Security.
“Security teams have traditionally assumed there is a human somewhere in the loop making decisions, pausing between steps and reacting to what happens,” Nahum says. “An agent can continuously investigate the environment, adapt and keep moving at machine speed. Incident response processes designed around human-paced attacks are going to struggle with that.”
The point in AEPD’s story where the AI compromised an identity, he says, is especially important. “Once an attacker or agent has valid credentials, a traditional control may simply see an authenticated user. The question becomes whether the behavior behind that identity still makes sense,” Nahum says. “What did it access? What changed? What actions followed? That is the same problem organizations already face with human insiders, except now the insider can be synthetic and operate continuously.”
In its security alert, AEPD highlighted the importance of securing digital identities and credentials against offensive AI. It also recommended that organizations review and potentially speed up their incident response times, and support manual intervention into data breaches with detection, containment, and response processes that work at machine speed.
Organizations don’t have much time left to implement these sorts of changes. “I suspect incidents like this will soon stop being noteworthy because an AI agent was involved,” Moody says. “They will become noteworthy because an AI agent wasn’t involved.”

Comments are closed