
Spain's Data Protection Agency (AEPD) has received the first notification of a personal data breach caused by an attack carried out by an artificial intelligence agent.
According to information provided by the affected organization, a third party used an AI agent based on a well-known language model to carry out different phases of the attack.
How the attack happened
The AEPD stresses that the information comes from the affected company's initial notification and still needs to be analyzed. It also notes that using a given AI model in an attack does not mean the model itself or its provider's infrastructure was compromised, nor that the tool was designed with malicious intent.
Why it matters
AI has long been used to craft phishing messages, analyze code, or make it easier to find vulnerabilities. The difference here is the level of autonomy.
AI agents can be given a goal, use different tools, and chain actions together based on the results they find, without needing human instructions for every step.
The AEPD notes that this first case does not yet amount to a statistical trend, but it does show that this type of attack is no longer a purely theoretical risk.
It also recommends that organizations specifically factor AI-assisted or AI-executed attacks into their risk assessments, since automation can significantly change the likelihood, speed and scope of an incident.
Attacks that go from weeks to hours
The case coincides with another incident analyzed by Unit 42, the research team at Palo Alto Networks. In September 2026, Unit 42 documented an intrusion in which an attacker used specialized AI agents to execute more than 50 MITRE ATT&CK techniques.
The agents mapped internal infrastructure, searched code repositories for credentials, and took part in different phases of the intrusion. The human attacker kept setting the objectives and making the key decisions, while the agents executed and adapted actions in real time.
How much can these breaches cost?
IBM's Cost of a Data Breach Report 2026 also shows the problem is growing: one in four malicious breaches analyzed was AI-enabled, up 56% from the year before.
These breaches had an average cost of $6 million, roughly a million more than the global average of $4.99 million. The study covers breaches suffered by 602 organizations worldwide between March 2025 and February 2026.
What should companies review?
The rise of more automated attacks makes it especially important to:
- Review access, identities and privileges.
- Protect credentials, API keys and tokens.
- Monitor for anomalous behavior.
- Fix vulnerabilities quickly.
- Keep backups and recovery plans up to date.
- Update risk assessments to account for AI's new capabilities.
The main takeaway is not that AI has replaced cybercriminals, but that it can automate much of their work and drastically shrink the time available to detect and stop an attack.
At Cloud Levante we work on this protection through SIEM services, pentesting, Disaster Recovery & Backup, and NIS 2 and ISO 27001 readiness — see our cybersecurity services.
