# AI-Driven Multi-Stage Data Breach Uncovered in Spain

*Published September 18, 2026*
*Source: [https://www.infosecurity-magazine.com/news/ai-agent-carries-out-multistage/](https://www.infosecurity-magazine.com/news/ai-agent-carries-out-multistage/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/ai-driven-multi-stage-data-breach-uncovered-in-spain) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Spain's Agencia Espanola Proteccion Datos (AEPD) has reported the country's first personal data breach powered by an AI agent. Francisco Pérez Bes, president of the AEPD, announced the incident, which involved an AI agent using a known language model to scan files and gain system access. Once inside, the AI agent autonomously identified application vulnerabilities, modified personal data, and accessed invoices.

The breach is still under investigation, but initial findings suggest the AI was deliberately used by a threat actor to execute various attack stages. Simon Phillips, CTO at CybaVerse, expressed concern over the possibility of threat actors bypassing the safety mechanisms of advanced AI models. He emphasized the need for organizations to understand AI's potential impact on their environments and prioritize defense measures.

Pérez Bes stated that this incident signifies a pivotal moment for Spain, transitioning AI from a theoretical concern to a tangible threat. He emphasized that AI-driven attacks should be included in risk analyses and that response times must be evaluated. The case highlights the critical role of digital identities and the necessity for rapid incident responses.

The AEPD concluded that AI agents entering the offensive landscape should prompt an immediate reassessment of security and data protection strategies. Data protection officers and managers must prepare for faster attacks while maintaining a strong understanding of data processing activities, minimizing data exposure, limiting access, addressing vulnerabilities, controlling suppliers, and being ready to respond effectively.
