started · updated
Spain reports first autonomous AI agent cyberattack
The Spanish Data Protection Agency (AEPD) has reported the first instance of a security breach executed by an autonomous artificial intelligence agent. The attacker used a known language model to infiltrate a system, identify vulnerabilities, and modify personal data and invoices.
The AI agent operated by scanning generic files to find login credentials, which it then used to gain access to the platform. Once inside, the tool autonomously identified application flaws to facilitate the intrusion. Francisco Pérez Bes, deputy at the AEPD, noted that while a specific language model was instrumentalized, this does not imply the model's provider was compromised or that the tool was designed for malicious use.
This incident marks a structural shift in cybercrime. Unlike previous uses of generative AI for phishing or code analysis, autonomous agents can independently plan intermediate tasks, execute code, and modify their behavior in real-time based on the requirements of the attack. This automation significantly increases the speed and scale of threats, potentially outpacing human response times.
Entities
Agencia Española de Protección de Datos · Francisco Pérez Bes · Spain