Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
government-diplomatic-threatai-enabled-threat-activitydata-exfiltration-methodmass-credential-exposure

Reports of Mexican Government Breach Allegedly Enabled by Anthropic Claude-Assisted Exploitation

Updated 3mo agoFirst seen Mar 1, 20262 sources

Reporting described a purported month-long intrusion into multiple Mexican government entities in which threat actors allegedly used Anthropic Claude to identify vulnerabilities and generate exploit code, resulting in claimed theft of ~150 GB of data. The campaign was reported to have affected Mexico’s federal tax authority and civil registry, as well as some state-level networks and Monterrey’s water utility, with alleged exposure of ~195 million records (taxpayer data, civil registry files, voter lists) and government employee credentials; the described technique involved prompting the LLM as if conducting authorized security research to bypass guardrails that would otherwise block requests such as log/command-history deletion.

Mexican agencies publicly disputed the incident, with the tax authority and national electoral institute reportedly dismissing the breach claims and Jalisco’s state government asserting any impact was limited to federal networks. Separate commentary and policy-focused coverage highlighted growing government sensitivity to reliance on Claude, including reporting that the Pentagon asked major defense contractors to assess their dependence on Claude—framed as potential precursor activity to a “supply chain risk” designation—amid tensions over Anthropic’s refusal to relax safeguards; other items in the set were unrelated human-interest or conference interview content and did not add technical corroboration of the Mexico intrusion claims.

Share:
Reports of Mexican Government Breach Allegedly Enabled by Anthropic Claude-Assisted Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 27, 20264mo ago

FBI warns Salt Typhoon activity is still ongoing

The newsletter summary said the FBI warned that Salt Typhoon operations remain active. This reflects an official warning that the threat activity had not ended.

Google disrupts UNC2814 campaign using Sheets for GRIDTIDE C2

Google was reported to have disrupted a long-running Chinese cyber-espionage operation tracked as UNC2814. The campaign allegedly used Google Sheets as command-and-control infrastructure for GRIDTIDE malware.

Google warns Gemini integration changes risk of some API keys

A newsletter summary said Google's integration of Gemini altered the risk posture of certain API keys that were previously considered safe for client-side use. It urged organizations to audit exposed keys and rotate them because they may now permit access to Gemini-related data.

Anthropic alleges distillation attempts by three Chinese labs

A newsletter summary reported that Anthropic alleged three Chinese laboratories attempted large-scale model distillation using fraudulent accounts. The item presents this as a disclosed concern around misuse of Anthropic's systems.

Mexican institutions deny or downplay reported breaches

Following reporting on the alleged intrusions, several Mexican institutions publicly denied or minimized the impact, including the tax authority and the national electoral institute. Jalisco's state government said only federal networks were affected.

Dec 31, 20256mo ago

Attackers allegedly exfiltrate 150 GB and 195 million Mexican records

According to the reported findings, the campaign compromised Mexico's federal tax authority, civil registry, some state governments, and Monterrey's water utility. The attackers allegedly stole about 150 GB of data, including roughly 195 million records such as taxpayer data, civil registry files, voter lists, and government employee credentials.

Dec 1, 20257mo ago

Intrusion campaign against Mexican government entities begins

A Gambit Security report, cited by Cybernews and SC Media, said a month-long campaign started in December targeting multiple Mexican government entities. The attackers allegedly used Anthropic's Claude model to identify vulnerabilities and help generate exploit scripts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
2 linked
Malware
1 linked
Affected products
1 linked
Fortigate
Organizations
12 linked
AnthropicCybernewsGambit SecurityTruffle SecurityChainalysisMazePalo Alto NetworksMedia LandAppleGoogleIPIDEAVeritasium
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.