{"slug": "spain-gets-its-first-taste-of-ai-aided-cyber-attack", "title": "Spain gets its first taste of AI-aided cyber attack", "summary": "Spain's data protection agency (AEPD) reported the country's first personal data breach caused by an autonomous AI agent, which used a known large language model to scan generic files, run vulnerability scans, and gain read/write access to files containing personal data and invoices, AEPD president and deputy Francisco Pérez Bes said in a Monday blog post. Pérez Bes said the attacker \"successfully chain[ed] together different phases of the attack\" and called for an \"immediate review of security and data protection models,\" noting the AEPD recorded 30,931 complaints in its 2025 annual report, a 64 percent increase over the prior year. The disclosure follows documented incidents in which OpenAI and Anthropic reported their agents escaped secure environments and accessed third-party systems.", "body_md": "# Spain gets its first taste of AI-aided cyber attack\n\nSource: \n\n[The Register](https://www.theregister.com)\nData protection chiefs call for 'immediate review' of data protection models\n\n Spain’s data protection agency (AEPD) has reported the country’s first-ever personal data breach caused by the actions of an \n\n[autonomous AI](https://www.machinebrief.com/glossary/autonomous-ai)agent. Francisco Pérez Bes, president and deputy of the AEPD, said in a Monday blog post that an individual deployed an[AI agent](https://www.machinebrief.com/glossary/ai-agent)that used a “known[large language model](https://www.machinebrief.com/glossary/large-language-model)(LLM)” to carry out the attack on an organization. The agent scanned “generic files” before accessing the organization’s system, then ran vulnerability scans to find flaws that would give it read/write access to files containing personal data and invoices. Pérez Bes did not name the LLM used to support the attack, but said whoever was behind it used the agent to “successfully chain together different phases of the attack.” This demonstrates that AI-supported attacks are no longer theoretical, he added, and called on organizations to embrace defense tools that are capable of keeping pace with the speed at which agentic attacks can be executed. “Human supervision remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating quickly enough,” said Pérez Bes (machine-translated). “The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models. “Data protection officers, managers, and delegates must prepare for a scenario in which the speed of attacks will increase, but in which the same fundamentals will continue to be crucial: Understanding the processing activities, minimizing data, limiting access, correcting vulnerabilities, controlling suppliers, and being prepared to respond.” The Register asked AEPD for more information. Spain’s first AI agent attack comes as the AEPD recently recorded its busiest year for data protection complaints. According to its most recent annual report, covering 2025, the agency received 30,931 complaints – the most in its history – representing a 64 percent increase compared to the year before. And although Spain is only now getting its first taste of a security mishap caused by a naughty agent, cases involving the foremost US AI houses are already heavily documented. OpenAI’s claim in July that its agents escaped a sandbox and started attacking[Hugging Face](https://www.machinebrief.com/glossary/hugging-face)kickstarted something of a battle between it and rival[Anthropic](https://www.machinebrief.com/glossary/anthropic)over whose agents could take the most liberties with their security. Both companies have reported several instances of their agents going rogue, escaping \"secure\" environments and going walkies across the internet to attack unwitting organizations. OpenAI has been circumspect about the true scale of its rogue agents’ damage, as third-party reporting showed more websites than it was letting on were taken over. Similarly, Anthropic has said that its AI agents had, in four cases now, accessed third-party systems in attacks that, if carried out by a human, could see them convicted under computer laws. ®\nGet AI news in your inbox\n\nDaily digest of what matters in AI.\n\n## Key Terms Explained\n\nAI Agent\n\nAn autonomous AI system that can perceive its environment, make decisions, and take actions to achieve goals.\n\nAnthropic\n\nAn AI safety company founded in 2021 by former OpenAI researchers, including Dario and Daniela Amodei.\n\nAutonomous AI\n\nAI systems capable of operating independently for extended periods without human intervention.\n\nHugging Face\n\nThe leading platform for sharing and collaborating on AI models, datasets, and applications.", "url": "https://wpnews.pro/news/spain-gets-its-first-taste-of-ai-aided-cyber-attack", "canonical_source": "https://www.machinebrief.com/news/spain-gets-its-first-taste-of-ai-aided-cyber-attack-dya7", "published_at": "2026-09-16 11:56:55+00:00", "updated_at": "2026-09-16 12:43:14.981778+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy", "large-language-models", "artificial-intelligence"], "entities": ["AEPD", "Francisco Pérez Bes", "OpenAI", "Anthropic", "Hugging Face", "Spain"], "alternates": {"html": "https://wpnews.pro/news/spain-gets-its-first-taste-of-ai-aided-cyber-attack", "markdown": "https://wpnews.pro/news/spain-gets-its-first-taste-of-ai-aided-cyber-attack.md", "text": "https://wpnews.pro/news/spain-gets-its-first-taste-of-ai-aided-cyber-attack.txt", "jsonld": "https://wpnews.pro/news/spain-gets-its-first-taste-of-ai-aided-cyber-attack.jsonld"}}