The Data Protection Agency (AEPD) has received the first notification about a possible cyberattack carried out by an autonomous artificial intelligence agent.
In the midst of panic about the reach of this technology and the implications of its uncontrolled development, the AEPD received a notification in which an autonomous agent is accused of illicitly accessing third-party data causing a data breach.
According to the Agency’s account, an attacker would have used this agent to successfully chain “different phases of attack”.
“The attacking agent started a search for vulnerabilities in generic files, and performed a correct login. Once it accessed the system, it began to autonomously search for vulnerabilities in the application, which, once achieved, allowed it to modify personal data and access invoices,” details the public body.
There are no clues about the companies involved or the model used, which is described as a “well-known language model,” making it likely to be one of the commercial chatbots.
Following this incident, the entity has called for extreme precautions and a review of companies’ action protocols, as the use of agents makes it necessary to speed up response procedures.
“This first notification does not allow for asserting a statistical trend, although it does constitute a significant signal that attacks supported by artificial intelligence have ceased to be a theoretical risk and are beginning to materialize in incidents affecting real personal data processing,” the institution points out.