4 min read

AI hacks system and accesses personal data in reported breach

Filip TRUȚĂ

September 17, 2026

AI hacks system and accesses personal data in reported breach

Spain’s privacy regulator has received a first-of-its-kind data breach notification involving an AI agent that allegedly sought vulnerabilities, gained access to a system and continued the attack with limited human intervention.

Key takeaways

  • Spain’s privacy regulator has received its first data-breach notification involving an attack carried out using an AI agent
  • The agent allegedly searched for vulnerabilities, successfully logged into a system and continued probing the application autonomously
  • The intrusion ultimately allowed the attacker to modify personal data and access invoices
  • The AEPD emphasizes that the incident is still under analysis and the information comes from the affected organization
  • Using a particular AI model does not mean the model or its provider was compromised
  • AI agents could accelerate familiar cyberattacks considerably by automating multiple stages of an intrusion
  • Organizations should reinforce identity protection, vulnerability management, access controls and automated detection and response

From AI assistant to AI attacker

Artificial intelligence is taking a more hands-on role in cyberattacks, with Spain’s data protection authority reporting a breach in which an AI agent allegedly carried out several stages of an intrusion autonomously.

The Spanish Data Protection Agency (AEPD) says it has received its first notification of a personal-data breach involving an attack executed through an AI agent, using a well-known large language model.

Generative AI is already part of the cybercrime toolbox. Criminals can use it to write convincing phishing messages, translate scams, analyze code, research targets and help identify vulnerabilities.

AI agents take that automation further.

Instead of simply answering a hacker’s questions or generating a piece of code, an agent can be given an objective, break it into individual tasks, use tools, execute commands, evaluate the results and decide what to do next.

That appears to be what happened in the incident reported to the AEPD.

The attacking agent began by searching for vulnerabilities in generic files and successfully logged into the targeted environment, the regulator says. Once inside, it autonomously searched the application for additional vulnerabilities.

After finding a way forward, the attack resulted in the modification of personal information and access to invoices.

In other words, the AI wasn't just telling someone how an attack might work – it was practically executing the intrusion.

Important caveats

The case comes with several important qualifications.

The AEPD says the information, which comes from the affected organization’s breach notification, still needs to be analyzed before definitive conclusions can be drawn. The regulator hasn't publicly identified the organization, the language model or the attacker. Nor does the use of a particular AI model mean that the model itself was hacked, that its developer's infrastructure was compromised, or that the technology was designed for malicious activity.

And while this is the first such incident reported to the AEPD, a single notification doesn't establish a wider statistical trend. What it does provide is another indication that agentic AI is moving beyond theoretical cybersecurity scenarios.

Cyberattacks at machine speed

The individual techniques involved aren't necessarily new. Attackers have long searched for vulnerabilities, stolen or abused credentials, probed applications and accessed sensitive information.

What changes is the speed and autonomy with which those steps can be chained together.

Spain's National Cryptologic Center (CCN) warned earlier this year that offensive AI can increase the speed, scale, precision and autonomy of established attack techniques. Its guidance highlights AI-assisted vulnerability exploitation, reconnaissance, malware creation, phishing and adaptive social engineering among the emerging risks.

Other evidence points in the same direction. Anthropic said in a September threat-intelligence report that it has observed cyber operations in which AI goes beyond answering questions and instead helps orchestrate or directly execute reconnaissance, exploitation, credential harvesting and other stages of attacks. Human operators still set objectives and retain control in the observed campaigns, but they increasingly delegate operational work to AI systems.

For defenders, the concern is that AI suddenly invents entirely new ways to break into computers and compress an attack that once required repeated human decisions into a much faster automated process.

The basics now become even more important

An open letter published last month by OpenAI signals this exact danger, warning that organizations have a “limited window” to address longstanding security weaknesses before advanced AI capabilities become more widely available to attackers.

Read: Big Tech calls for cyber-defense before AI attacks surge

The AEPD says organizations should account for AI-assisted and AI-executed attacks in their risk assessments because automation can alter the likelihood, speed and scope of a breach.

Security teams also can't rely solely on a person noticing suspicious activity and responding manually. Automated attacks increasingly call for automated detection and containment that operates at comparable speed.

The CCN recommends reinforcing fundamentals, including identity and access management, vulnerability management, network segmentation, continuous monitoring and secure-by-default systems.

For organizations handling personal information, those protections also matter from a privacy perspective. Under the GDPR, organizations must notify the relevant supervisory authority when a personal-data breach is likely to pose a risk to people's rights and freedoms, generally within 72 hours of becoming aware of it.

Bottom line

AI isn't replacing the cybercriminal behind the keyboard, but it is increasingly capable of doing more of the work between the attacker's instructions.

In this case, the agent allegedly didn't just provide advice – it searched, adapted and acted against a real system until personal information became accessible.

The AEPD is still examining exactly how this incident happened.

On topic:

Big Tech calls for cyber-defense before AI attacks surge

Apple Watch can now remember conversations. What could go wrong?

AI is turbocharging scams worldwide, Interpol warns

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader