{"slug": "ai-agent-runs-first-end-to-end-breach-in-spain", "title": "AI agent runs first end-to-end breach in Spain", "summary": "Spain's data protection agency (AEPD) reported the country's first data breach carried out end-to-end by an AI agent, which performed reconnaissance, logged in, probed an application and modified data without any human operator at any step. In a separate incident the same week, researchers at Hacktron documented an attack chain that began with flaws in the libheif and ImageMagick image-decoding libraries and moved through a misconfigured OpenAI SSO into internal repositories, with the exploit built using Claude Opus 5. A third case involved an attacker who used a modified version of Claude Code to brute-force more than 87,000 IP addresses and rent them as proxies, earning $202,000 since 2024.", "body_md": "The Spanish Data Protection Agency has reported the first data breach in Spain executed end-to-end by an AI agent (Source: securityweek.com).\n\nThe agent did reconnaissance, logged in, probed the application and modified data with no human operator at any step.\n\nThat is what is new. Until now, the cases that got published always had a person deciding the next move, even remotely and with a model's help.\n\nNot here. The agent closed the entire chain.\n\nThe same week, researchers at Hacktron documented another chain worth reading slowly (Source: securityweek.com).\n\nIt started in libheif, the library that decodes HEIF images, and in ImageMagick, the classic conversion tool. A flaw in that image processing opened the first door.\n\nThe second door was not a flaw, it was a configuration. OpenAI's SSO was misconfigured, and that misconfiguration let the chain keep moving into internal repositories.\n\nThey used Claude Opus 5 to build the exploit.\n\nLook at the sequence. A flaw in a decoding dependency, a service that shares identity with another, and an AI tool that speeds up the hard part. None of the three steps is exotic on its own. Together they form a chain that enters where nobody looks.\n\nWhat stands out is not the sophistication. It is that the chain holds on pieces that have been in any company's inventory for years.\n\nBoth stories share a shape. An agent or an automated chain walks through steps that used to require human hands, and it does so at a speed classic controls were not designed to see.\n\nIn the AEPD case, the agent needed nothing strange. It did what a patient attacker would do, but without pauses and without getting tired.\n\nIn the Hacktron case, the AI did not replace the attacker. It took away the heavy work of building the exploit, which is exactly the part that used to filter out amateurs.\n\nI have checked it myself, without being an expert in anything: the entry barrier is now very low and the volume of attempts rises.\n\nAI agents as attackers? The agent is also the attacker's tool, and this week there are two clear examples.\n\nThe first is Hacktron, with Claude Opus 5 building the exploit.\n\nThe second is LeakySensey, an attacker who compromised more than 87,000 IP addresses through brute force against devices with PPTP and L2TP and credentials like admin123 (Sources: escudodigital.com, cybernews).\n\nHe rented them as proxies and made 202,000 dollars since 2024. He automated the operation with a modified version of Claude Code, presumably local.\n\nThere is the direction that matters. It is not that AI attacks on its own, it is that a single operator scales what used to require a team.\n\nMy reading is that the problem is not the agent's autonomy, it is the surface we leave for it. And skipping the catastrophic tone.\n\nA misconfigured SSO is a door you share between services. If the agent enters through it, it enters all of them at once.\n\nAn unpatched decoding dependency is a door almost nobody looks at. libheif does not come up in risk meetings.\n\nAnd a VPN with PPTP or L2TP and default credentials is a door that has been open for years and nobody has closed because nobody uses it.\n\nThe three controls that would have stopped these attacks are concrete. Phishing-resistant MFA, isolation of services that share SSO, and patching of image decoding dependencies.\n\nNone is expensive. None is new. The problem is that none is on this week's priority list.\n\nI would set up a container with an old version of ImageMagick and libheif, feed it malformed HEIF images and see what happens.\n\nI would do it on an isolated network, with no internet egress, because the goal is to see the behavior, not to reproduce the exploit.\n\nI would watch whether the process crashes, whether it writes anything outside its directory or whether it opens a connection it should not.\n\nWith that I would have a cheap conclusion. If the service that decodes images has write permissions where it should not, the library flaw stops being a flaw and becomes a breach.\n\nThe lesson of the week is not that AI attacks on its own. It is that the doors we have left open for years are now walked through at a speed we had not seen.\n\nClosing three of them costs less than explaining why we did not.\n\nOriginally published at [https://sammideblas.com/notas/ai-agent-runs-first-end-to-end-breach-in-spain](https://sammideblas.com/notas/ai-agent-runs-first-end-to-end-breach-in-spain)", "url": "https://wpnews.pro/news/ai-agent-runs-first-end-to-end-breach-in-spain", "canonical_source": "https://dev.to/analista_83/ai-agent-runs-first-end-to-end-breach-in-spain-4g2d", "published_at": "2026-09-21 10:42:14+00:00", "updated_at": "2026-09-21 10:54:33.791608+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence"], "entities": ["Spanish Data Protection Agency", "AEPD", "Hacktron", "libheif", "ImageMagick", "OpenAI", "Claude Opus 5", "Claude Code"], "alternates": {"html": "https://wpnews.pro/news/ai-agent-runs-first-end-to-end-breach-in-spain", "markdown": "https://wpnews.pro/news/ai-agent-runs-first-end-to-end-breach-in-spain.md", "text": "https://wpnews.pro/news/ai-agent-runs-first-end-to-end-breach-in-spain.txt", "jsonld": "https://wpnews.pro/news/ai-agent-runs-first-end-to-end-breach-in-spain.jsonld"}}