September 20, 2026, 1:02 pm | Read time: 2 minutes
An AI system in Spain has independently carried out a cyberattack on a company for the first time. The Spanish data protection authority AEPD sees this as a new threat, as attacks could occur much faster in the future.
AEPD reports the first confirmed case of an autonomous cyberattack by an AI agent. According to the authority, an attacker used a system based on a large language model that autonomously executed various steps of a hacking attack. The human only provided the target, and the AI took over the execution.
The starting point was publicly accessible documents from the affected company. The agent found access data in them, which allowed it to log into internal systems. It then searched for further vulnerabilities and exploited one of them. This way, the system obtained additional information and was able to alter personal data.
Experts See a Turning Point
For security experts, the incident marks a new phase of cybercrime. Gene Moody from the security company Action1 explains that AI agents can analyze multiple targets simultaneously, try different attack paths, and continuously adapt their strategy. This could make attacks significantly more efficient than before.
Aviv Nahum from Above Security also warns of the consequences. Traditional protection mechanisms are often geared toward human attackers, who have limited resources and working hours. In contrast, an AI agent can operate around the clock and make decisions within seconds. As early as June, the Spanish National Cryptology Center CCN warned of the increasing use of AI in ongoing attack campaigns.
Companies Must Adapt Their Defense
The AEPD urges companies to adapt their security strategies to this development. Risk analyses should explicitly consider AI-supported attacks in the future. At the same time, response times must decrease, as human processes are often too slow against automated attacks.
Also interesting: AI develops its own language–researchers don’t understand it
Compromised access data is particularly critical. If an AI agent gains access to an account, it can move through numerous systems in a very short time. The authority therefore recommends more automated detection and defense mechanisms. According to many experts, the incident shows that AI is playing an increasingly important role not only in defending networks but also as a tool for attacks.