The First Autonomous AI Cyberattack in Spain: The AEPD Raises All Alarms and Demands a Rethink of Risk Analysis

The First Autonomous AI Cyberattack in Spain: The AEPD Raises All Alarms and Demands a Rethink of Risk Analysis

  • 22/Sep/2026
  • ForgeNEX by ForgeNEX
  • AI

Artificial intelligence has ceased to be a support tool and has become a main actor in the cyber threat landscape. The Spanish Data Protection Agency (AEPD) has received the first notification of a personal data breach in which the incident was executed entirely by an AI agent. The attack, carried out through a well-known language model, marks a turning point in how organizations must approach security and privacy.

la-apep-ia-pide-incorporar-los-ataques-asistidos-o-0.jpg

According to details provided by the Agency, the AI agent performed a successful login after searching for vulnerabilities in generic files. Once inside the system, and completely autonomously, it began exploring the application in search of flaws that would allow it to modify personal data and access invoices. What is truly relevant from a data protection perspective is not the technique used, but the use of an AI agent by a third party as an instrument to successfully chain different phases of the attack, from initial reconnaissance to the exfiltration of sensitive information.

AI as a Threat Multiplier

In statements to ComputerWorld, Miguel Recio, president of the Spanish Professional Association of Privacy and Artificial Intelligence (APEP·IA), was blunt: “the qualitative change introduced by agents is that AI increases the speed, scale, and adaptability of already known malicious techniques, reducing the time available to detect and contain impacts.” This statement sums up the essence of the problem: we are not facing a new type of vulnerability, but an exponential acceleration of existing ones.

This incident confirms the need to expressly incorporate AI-assisted or AI-executed attacks into risk analyses of data processing. According to Recio, it is not enough to include a generic reference to malware, phishing, or unauthorized access. The dynamic and adaptive nature of AI agents forces a thorough review of the procedures adopted to respond to attacks, as well as the implementation of detection, containment, and response mechanisms capable of operating quickly enough to counter a threat that acts at machine speed.

“It is necessary to include threats derived from AI-based cyberattacks in risk analysis, reviewing it when necessary, and adopt a proactive approach,” adds Recio. This proactive vision implies anticipating the attacker's moves, something that until now was easier when the human factor limited execution speed.

Insufficiencies of Traditional Security Models

APEP·IA acknowledges that procedures designed for manually executed attacks may prove insufficient when an agent simultaneously analyzes multiple assets, tests different access paths, and rapidly adapts its behavior. The agency has identified four main shortcomings in current approaches:

  • Human response times: The speed of an AI agent far exceeds the reaction capacity of security teams that depend on manual triage and escalation processes. While an analyst evaluates an alert, the agent has already tested dozens of different attack vectors.
  • Detection based on signatures or static patterns: An agent that adapts its behavior based on what it finds can evade detection systems that rely on known signatures or predefined attack patterns. Generative AI is capable of mutating its tactics in real time.
  • Reactive incident management: APEP·IA calls for mechanisms that enable incident management responding to the reality of such attacks, rather than merely having manual notification and escalation procedures.
  • Insufficient monitoring: For Miguel Recio, this “must be continuous, like a dynamic security management process based on monitoring critical indicators and patching vulnerabilities.”

These shortcomings are not mere technical details; they represent significant gaps in the security posture of any organization that handles personal data. The interconnection of systems and the adoption of cloud architectures have expanded the attack surface, and AI acts as a catalyst that exploits these weaknesses on an unprecedented scale.

la-apep-ia-pide-incorporar-los-ataques-asistidos-o-1.jpg

The Critical Role of Digital Identities and Credentials

In this context, digital identities and credentials take on capital importance. An agent that obtains an account, an API key, or a token with excessive permissions can operate at machine speed and access different services before the organization detects anomalous behavior. Identity management thus becomes the first line of defense.

Miguel Recio has called for giving the role they deserve to additional controls such as multi-factor authentication (MFA), periodic credential rotation and suspension — “if they are not used for a period of time,” he specifies —, real-time anomaly detection, access segmentation and zero trust, or activity logging and auditing to monitor, analyze, and investigate improper access. These measures, although known, are often implemented incompletely or relaxed in rapidly evolving environments.

Attack speed will only increase. Consequently, the president of APEP·IA also asks data protection officers, controllers, and processors to prepare for a scenario in which attack speed will be ever greater. He considers it crucial to know the processing activities, minimize data, limit access, correct vulnerabilities, control suppliers, and be prepared to respond. “Some internal policies and measures to adopt are drawing up an inventory and governance of AI agents, data protection by design and by default, supply chain control, or continuous updating of security incident response protocols,” he concludes.

These recommendations resonate with best practices in business process automation with n8n and AI, where workflow orchestration must be accompanied by robust safeguards. The integration of intelligent agents in corporate environments, whether for marketing tasks or infrastructure management, requires a security-by-design approach that considers AI-specific risks.

The Regulatory Gap: The Only Place That Was Open

Fernando Maldonado, principal analyst at Foundry Spain, offers a revealing perspective on why this incident has come to light. He explains that the first official trace of AI used to attack in Spain has not appeared where one would expect, in the cybersecurity registry, but in the one next to it: the data protection registry. “Not because it is the right place, but because it is the only one that was open,” he admits.

In his opinion, the difference between the two registries is not one of importance, but of calendar. Maldonado recalls that the European Data Protection Regulation has required since 2018 that any company suffering a personal data breach notify it within 72 hours. “Eight years in operation, with the Agency receiving notices daily,” he specifies. Meanwhile, the cybersecurity regulation that would do the same for technical incidents, NIS2, requires an even shorter period, 24 hours for the first alert, but it is not yet in force in Spain. “The consequence is that an attack can leave an official trace through one channel and not the other, and the criterion that decides which one is not the nature of the attack, but which of the two laws is in force.”

According to Maldonado, this attack touched personal data. “That is why we know about it,” he emphasizes, and adds: “If the same agent had encrypted a system or brought down a website without reaching the data, and the victim were a normal company, today there would be no public trace of it anywhere.” Similarly, he recalls that “notification does not measure what happens; it measures what there is an obligation to report. And today, for most Spanish companies, that obligation comes through only one channel: personal data.”

This regulatory asymmetry leaves a dangerous blind spot. The lack of a mandatory technical registry for incidents that do not affect personal data means that many successful attacks, especially those targeting critical infrastructure or intellectual property, remain hidden. NIS2, which would harmonize these obligations, is two years late in its transposition, leaving companies and authorities without a complete view of the threat landscape.

la-apep-ia-pide-incorporar-los-ataques-asistidos-o-2.jpg

The Bottleneck That Disappears

The novelty for Fernando Maldonado is the role of the agent. “Writing phishing emails, translating frauds, finding flaws in code, all that was already done with generative models, with AI as an assistant to a human who directed it,” he acknowledges. “An agent changes that role. It receives an objective and chains only the steps: it plans, tests, interprets what it finds, and adjusts its next move without anyone telling it how. In this case, it searched for the vulnerability, entered, and once inside, it searched again on its own. What previously required an attacker sitting at the controls is now done by a machine that works at its own speed.”

Therefore, for Maldonado, it is not a new capability. “It is the same one, without the bottleneck of the human hand. And that bottleneck was, until now, a good part of what gave time to detect an attack.” The elimination of human intervention in the critical phases of the attack drastically reduces the window of opportunity for defense. Traditional security systems, designed to detect human behavior patterns, now face a threat that does not tire, does not make mistakes due to haste, and can operate 24/7.

This paradigm shift demands a thorough review of cybersecurity strategies. Defense automation, the use of AI to counter AI, becomes imperative. As in the field of advanced home automation with Home Assistant for offices, where security and professional deployment are crucial, in the world of cybersecurity the integration of intelligent systems must be accompanied by an equally intelligent layer of protection.

The Calendar and the Machine

What will happen from now on? Will this attack remain an anecdote, or is it rather the beginning of a new modality? In the analyst's opinion, three things will tell whether it is the former or the latter. “The first is whether more notifications like this reach the Agency: the step from one to several is what turns a signal into a pattern, and it is APEP·IA itself that has said that today it is not yet one. The second is whether the cybersecurity law is passed before or after the blind spot costs something expensive to tell. And the third is the underlying one: whether when the technical registry finally exists, it begins to fill with cases that had been occurring for some time without anyone seeing them.”

For the analyst, this last possibility is the uncomfortable one. “It may be that the first AI attack notified in Spain is not the first that occurred, but the first that fell into the only net that was set. Those that did not touch personal data, and hit a company with no obligation to report, are not in any account. We do not know how many there are. We know that the law that would tell us has been waiting for two years, and that the machine that executes them waits for no one,” he reflects.

The conclusion is clear: AI has leveled the playing field, but not in favor of defenders. Organizations must assume that autonomous attacks are a reality and that the only way to mitigate their impact is through a combination of advanced technology, agile processes, and a proactive security culture. The reaction window is narrowing, and time is on the side of machines.


Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.

Share: