Security

First data breach caused by an autonomous AI agent in Spain: what the AEPD says and what to do

An AI agent obtained valid credentials, got into a system, modified personal data and accessed invoices. What matters for a small business isn't fear, but what changes in its security plan.

Published on October 7, 2026 · The mitza.es team

On 15 September 2026, the Spanish Data Protection Agency (AEPD) explained on its blog the first personal data breach notified to it in Spain in which an artificial intelligence agent autonomously carried out several phases of an attack. Neither the affected organisation nor the language model used has been identified. The information reached the agency because the organisation itself reported the breach and, according to the AEPD, it still has to be analysed: for now there are no closed conclusions and no penalty. It is covered by, among others, Euronews, Moncloa and MuyComputerPro (all in Spanish).

What happened, according to the AEPD

A third party used an AI agent, backed by a well-known language model, to "successfully chain together different phases of an attack". According to the sources that reproduced the agency's note, the agent:

  • Searched in an automated way through general-purpose files until it obtained valid access credentials.
  • Logged in successfully to one of the organisation's systems.
  • Kept exploring the application on its own and detected security flaws.
  • Used those flaws to modify users' personal data and access invoices.

The AEPD stresses that the use of a particular model "does not mean that the model or its provider's infrastructure were compromised, nor that the tool was designed to carry out malicious activities": the agent was an instrument in someone else's hands. The sources don't say which files the credentials came from or how many people were affected.

Why it matters even if it's an isolated case

What follows is our reading, not a conclusion of the agency. The agent did nothing a human attacker couldn't do: look for credentials, get in, explore and exploit a flaw. The difference is scale and speed. There is no longer a need to spend hours of skilled work on each target, so small businesses stop being "too uninteresting". The cyberattack on Renfe and Adif that we analysed recently points in the same direction: according to the reconstructions we reported, an AI agent autonomously located the vulnerability.

And a detail that is easy to overlook: the way in was valid credentials, not an exotic flaw. That puts the focus back on the basics: unique passwords, two-factor authentication and accounts that shouldn't still be active.

What the AEPD asks for

As reported by Escudo Digital and the other sources cited, the agency asks controllers and processors to:

  • Expressly include attacks assisted or carried out by AI in their risk analyses.
  • Strengthen control of identities and credentials.
  • Apply the principle of least privilege.
  • Have automatic detection and interruption tools able to respond in real time.
  • And, more generally: know their data processing, minimise data, fix vulnerabilities, control suppliers and be ready to respond.

Five concrete measures for a small business

These are our own recommendations, designed for a small business and aligned with what the agency asks for:

  • Unique credentials and two-factor authentication. A different password for every service, stored in a password manager, and two-factor on email, the website admin panel, invoicing and online banking. If one of your passwords is already circulating in an old leak, an automated agent will find it before a person does. You can check your email addresses at Have I Been Pwned and change whatever turns up.
  • Least privilege. Everyone accesses only what they need, administrator accounts are kept separate from everyday ones and accounts of former employees or contractors are closed.
  • Check what is exposed. Web applications, panels and old copies reachable from the internet are the first thing an agent looks for. A website security audit reviews exactly that: outdated plugins, configuration, access and backups.
  • Logs and alerts. Turn on alerts for unusual logins (country, time, repeated attempts) and decide who looks at them. A log nobody reads detects nothing.
  • Response plan. Know who to call, how to isolate the system and when to notify. The GDPR requires breaches that pose a risk to individuals to be reported to the AEPD without undue delay and, where feasible, within 72 hours of becoming aware of them (Article 33). A cyber insurance policy can cover part of the costs.

More context

The AEPD has not announced a penalty in this case, but it has fined large companies this year for breaching the GDPR, as we covered in the fines on Vodafone, Amadeus and Aena. And AI-driven attacks aren't only agents getting into systems: phishing and deepfakes are growing too. If your company works with large customers, also look at what NIS2 will require.

How we can help

If you want to know what an automated attacker sees when it looks at your website, our website security audit reviews plugins, configuration, access and backups, and gives you a report prioritised by real risk. And if your website is in order but nobody looks after keeping it up to date, we have a website maintenance service for small businesses.

Do you know what an automated attacker can find on your website?

We review your website and access points and give you a report prioritised by real risk.

No spam. No sales calls. Just your personalised reply.