In short: On 14 September 2026 Spain's data protection authority AEPD received the first officially documented personal data breach notification in which the attack was carried out by an autonomous AI agent — with no human operator directing each step. The agent logged in, scanned for vulnerabilities, altered personal records, and accessed invoices. Regulators are calling it a turning point for cyber threats globally.
The attack chain: what the AI agent did
A Spanish organisation notified the Agencia Española de Protección de Datos (AEPD) of a personal data breach in which the attacker reportedly deployed a large language model (LLM)-powered autonomous agent. The agent executed a multi-step attack chain without manual intervention: it logged into the target system using what appear to be compromised credentials, scanned generic shared files for vulnerabilities, autonomously probed applications for exploitable flaws, modified personal data records, and then accessed financial documents including invoices.
The identity of the victim organisation and the exact volume of data compromised remain undisclosed while AEPD's investigation continues. What is clear is the method: this attack represents a qualitative shift from AI-assisted hacking — where a human uses AI as one tool — to fully agentic, end-to-end autonomous execution. Check whether your accounts are exposed via our security blog.
Why this changes the threat landscape
AEPD deputy director Francisco Pérez Bes explained what makes an agent different: "An agent can receive a goal, plan intermediate tasks, use tools, execute code, consult sources, interpret results, and autonomously modify its actions based on what it finds." An AI agent can "simultaneously analyse assets, test access methods, and adapt behaviour" — compressing hours of human work into seconds.
The agency issued a stark warning: "AI does not create new threats, but it can increase the speed, scale, and adaptability of cyberattacks." This is not an isolated signal in 2026: Hugging Face disclosed an AI agent breach in July, and security evaluations have documented LLM-based agents gaining unauthorised access to test systems. The Spanish incident is the first to reach a data protection regulator as a formal breach notification.
What this means for your personal data
An AI agent does not tire or get distracted. Given the objective of compromising a system, it methodically works through attack vectors, adapts after each failure, and moves to the next approach — all at machine speed. Traditional monitoring systems may not react quickly enough to catch every step of a fluid, autonomous intrusion.
AEPD highlighted a critical entry point: most successful AI-powered attacks begin with compromised credentials — stolen in past breaches, captured through phishing, or extracted by malware. Once an agent holds valid credentials, it works the rest autonomously. If your data has appeared in any previous leak, the risk is not abstract.
How to protect yourself
Strengthen your digital identity. AEPD named weak or reused credentials as the primary entry point for AI agents. Use a password manager with unique, strong passwords per service — one leaked password must not unlock multiple accounts. Enable two-factor authentication everywhere: even with a valid password, an agent cannot pass a hardware key or authenticator code alone.
Monitor for data leaks. Regularly check whether your email addresses appear in breach databases (services such as HaveIBeenPwned). If found, rotate passwords immediately and revoke active sessions across all devices.
Encrypt traffic on untrusted networks. An AI agent travels over the network — that is its transport layer. A VPN tunnel makes your connection opaque to observers at the network level: your ISP and the operator of a public Wi-Fi cannot see which services you reach or intercept login sessions. LiMP VPN encrypts traffic on iOS and Android with a strict no-logs policy — a necessary layer whenever you work outside a trusted network.
Act on breach notifications. Organisations are increasingly required to notify regulators when breaches occur. If you receive such a notification, treat it as urgent: change the password, revoke all sessions, and audit linked accounts for unauthorised activity.
What regulators are signalling: the road ahead
AEPD called on organisations to immediately review their security models: "The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models." Human oversight remains essential, but the agency stressed it "must be supported by detection, containment, and response mechanisms capable of operating quickly enough" to match machine-speed attacks.
This Spanish precedent will likely shape how data protection authorities globally approach AI-enabled breaches. Stay up to date on privacy threats and how to defend against them on our features page.
