Skip to content
Spain gets its first taste of AI-aided cyber attack

Spain gets its first taste of AI-aided cyber attack

Theregister • September 16, 2026

Ministry of Justice apologizes after court staff accessed Southport victims' files 4 hours ago

Ministry of Justice apologizes after court staff accessed Southport victims' files

Mythos has made 2026 patching hell. It might make 2027 a breeze 9 hours ago

Mythos has made 2026 patching hell. It might make 2027 a breeze

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches 17 hours ago

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

AI networking startups race to replace Nvidia's NVLink 18 hours ago

AI networking startups race to replace Nvidia's NVLink

Low-quality casino sites conceal highly dangerous threat actors 19 hours ago

Low-quality casino sites conceal highly dangerous threat actors

Spain’s data protection agency (AEPD) has reported the country’s first-ever personal data breach caused by the actions of an autonomous AI agent.

Francisco Pérez Bes, president and deputy of the AEPD, said in a Monday blog post that an individual deployed an AI agent that used a “known large language model (LLM)” to carry out the attack on an organization.

The agent scanned “generic files” before accessing the organization’s system, then ran vulnerability scans to find flaws that would give it read/write access to files containing personal data and invoices.

Pérez Bes did not name the LLM used to support the attack, but said whoever was behind it used the agent to “successfully chain together different phases of the attack.”

This demonstrates that AI-supported attacks are no longer theoretical, he added, and called on organizations to embrace defense tools that are capable of keeping pace with the speed at which agentic attacks can be executed.

“Human supervision remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating quickly enough,” said Pérez Bes (machine-translated).

“The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models.

“Data protection officers, managers, and delegates must prepare for a scenario in which the speed of attacks will increase, but in which the same fundamentals will continue to be crucial: Understanding the processing activities, minimizing data, limiting access, correcting vulnerabilities, controlling suppliers, and being prepared to respond.”

The Register asked AEPD for more information.

Spain’s first AI agent attack comes as the AEPD recently recorded its busiest year for data protection complaints.

According to its most recent annual report, covering 2025, the agency received 30,931 complaints – the most in its history – representing a 64 percent increase compared to the year before.

And although Spain is only now getting its first taste of a security mishap caused by a naughty agent, cases involving the foremost US AI houses are already heavily documented.

OpenAI’s claim in July that its agents escaped a sandbox and started attacking Hugging Face kickstarted something of a battle between it and rival Anthropic over whose agents could take the most liberties with their security.

Both companies have reported several instances of their agents going rogue, escaping "secure" environments and going walkies across the internet to attack unwitting organizations.

OpenAI has been circumspect the true scale of its rogue agents’ damage, as third-party reporting showed more websites than it was letting on were taken over .

Similarly, Anthropic has said that its AI agents had, in four cases now , accessed third-party systems in attacks that, if carried out by a human, could see them convicted under computer laws. ®

SpaceX aims Starship for orbit on September 22

Flight test 14 angling for 10 hours in space and a splashdown in the Pacific

AWS says wartime damage means some Middle East cloud resources are gone for good

Iranian strikes overwhelmed regional redundancy in Bahrain and left one UAE Availability Zone inaccessible

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

Spain gets its first taste of AI-aided cyber attack

Data protection chiefs call for 'immediate review' of data protection models

Open weights are not open source: Why AI's favorite label is under dispute

Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter

Logitech releases the MX Keypad to keep idle fingers busy

It looks like you're trying to write some code. Perhaps a shortcut is in order?

SAAS Salesforce staggers back to feet after global outage

Salesforce staggers back to feet after global outage

databases Oracle celebrates banner quarter with another round of layoffs

Oracle celebrates banner quarter with another round of layoffs

NETWORKS Virgin Media offloads email services to third-party provider

Virgin Media offloads email services to third-party provider

CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

software Another Microsoft team admits it’s struggling to handle flood of AI-generated code

Another Microsoft team admits it’s struggling to handle flood of AI-generated code

virtualization VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models

Spain gets its first taste of AI-aided cyber attack

Data protection chiefs call for 'immediate review' of data protection models

SYSTEMS AI networking startups race to replace Nvidia's NVLink Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack

AI networking startups race to replace Nvidia's NVLink

Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack

AI AND ML Anthropic and OpenAI look to Uncle Sam to make them too big to fail American model devs are trying to convince Washington to cement their dominance

Anthropic and OpenAI look to Uncle Sam to make them too big to fail

American model devs are trying to convince Washington to cement their dominance

on-prem Datacenter developers want your backyard. FAS says negotiate harder Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

Datacenter developers want your backyard. FAS says negotiate harder

Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

LEGAL Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late

Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

A real alternative to running some kind of FOSS Unix clone

Extracted Entities

Countries (2)

MITRE ATT&CK (1)

Platforms (1)

Ransomware Groups (1)