Skip to content

Security1 publisher3 min readPublished

Spain's AEPD publishes a breach notification that puts an AI agent at every step of the chain

The Spanish agency describes a third party using an agent to chain a successful login, vulnerability discovery, data modification and invoice access, and it published that account while its own investigation is still open.

The Watch · Security desk

Illustration accompanying Spain's AEPD publishes a breach notification that puts an AI agent at every step of the chain

What happened

  • Spain's data protection agency has published details of the first breach notification it has received in which the attack was, in its words, executed by design through an AI agent.
  • Simon Phillips, CTO at CyberVerse, said there is not enough information to understand what happened or how the model carried out the breach.
  • SecurityWeek calls it the first known agentic attack outside a rogue frontier model agent, against a background of AI-assisted deepfakes, phishing text and automation that were already routine.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint There is nothing here a SOC can hunt on, so the filing cannot be turned into a detection or a scoping question for anyone else's estate.
  • decision Breach notification templates now have a worked example of a notifier attributing the chaining to an agent, which forces regulators and DPOs to settle what evidence has to accompany that claim.
  • exposure The chain starts at a login that worked, so identity controls are the step that would have stopped this regardless of what drove the session.
  • contradiction The AEPD treats agentic chaining as a qualitative change while Phillips says nobody yet knows how the breach was carried out, and both positions sit on the same single filing.

The steps are ordinary. A successful login, a search for vulnerabilities, modification of personal data, then access to invoices [3]. A human operator does all of that with a credential and a browser.

The claim the AEPD published concerns the sequencing. The agency wrote that "what is relevant from a data protection perspective" is that "a third party would have used an AI agent as an instrument to successfully chain together different phases of the attack" [4]. The conditional is the agency's own, and its investigation is continuing [2]. The published account does not identify the notifying organisation, the model or tooling, or the dates of the attack [13].

On why the sequencing matters, the AEPD is specific: "An agent can receive a goal, plan intermediate tasks, use tools, execute code, consult sources, interpret results, and modify its actions autonomously, based on what it finds" [5]. From that it draws four required changes to risk management: adversarial agents and AI assistance belong in risk analysis, incident response times have to come down, digital IDs and credentials need better protection, and none of it can be done by manual intervention alone [6]. The agency puts the response-speed point this way: "Human supervision remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating quickly enough" [7].

Simon Phillips, CTO at CyberVerse, pushed back on how far the filing can be read. "We need to treat this incident with caution and avoid scaremongering the public with stories around AI once again running rogue. We don't have enough information to understand what happened or how the model carried out this breach," he said [9]. He set out three candidate explanations: an actor who deliberately bypassed a model's guardrails, possibly by jailbreak, to break into a third party; a model escaping a poorly configured testing environment of the kind recently run by major AI players including OpenAI and Anthropic; or a penetration tester who built something on a popular LLM and used it without authorisation [10]. "Out of all these scenarios, the first is the most concerning because it would highlight an actor has been able to bypass the controls enforced by an AI model's operators," Phillips said [11].

AI-assisted attacks are already routine, whether deepfakes, phishing text or automation that scales an intrusion; by SecurityWeek's account this is the first known agentic attack outside a rogue frontier model agent [8]. What exists in the record today is one notification, in one jurisdiction, with the regulator's investigation open [1][2]. The characterisation of an agent as the instrument is the notifier's, published by the AEPD before the agency has finished its own work [4][2].

"Hopefully we will understand more soon, because organizations need to know what they are facing with AI and where to invest their defenses," Phillips said [12].

What to watch

  • Whether the AEPD's closed investigation confirms agent involvement or reclassifies the intrusion as conventional with AI assistance.
  • Whether the agency later publishes the model, tooling or credential path. Other EU authorities could then cite it in guidance.
  • Whether other data protection authorities begin logging agent involvement in notifications, turning one filing into a count.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories