A Spanish organization experienced a personal data breach due to an AI system, which was under the supervision of humans This article explores ai driven cyberattacks. . On September 14, Spain's Data Protection Agency (AEPD) disclosed a breach report from an undisclosed entity, which describes an incident where an unidentifiable hacker utilized a "well-known language model" to infiltrate corporate personal data repositories.

The agency notes that AI's impact extends beyond the emergence of new threats, as it enables the rapid, scalable, and automated execution of known techniques, significantly shortening the time between vulnerability identification and exploitation.

According to CCN's report, "Combining open-source intelligence with direct reconnaissance against infrastructure allows attackers to precisely map digital assets like websites, programming interfaces, cloud services, or infrastructure-as-a-service environments." The attacker initially instructed their AI to search for vulnerabilities in generic files from a victim organization. "However, once inside the corporate application, our enterprising AI attacker probed the environment, finding vulnerabilities that allowed a human owner to modify personal data and access invoices."

Related: Cyber Attacks Target South Korean Media and Automotive Sectors. Stories of AI-driven cyberattacks now feel less shocking compared to earlier this year in 2026.

In this future, where autonomous systems can seamlessly link familiar cyberattack steps without human intervention, "Defenders now have a shorter time horizon," says Aviv Nahum, co-founder and CEO at Above Security. What actions followed?