Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activitygovernment-diplomatic-threatmass-credential-exposuredata-exfiltration-method

AI-Assisted Intrusions Against Mexican Government Agencies Using Anthropic Claude and OpenAI ChatGPT

Updated 1mo agoFirst seen Mar 6, 202614 sources

Researchers at Gambit Security reported that a small group of attackers used LLMs—including Anthropic Claude and OpenAI ChatGPT—to help compromise at least nine Mexican government agencies, stealing large volumes of sensitive records including ~195 million identity and tax records, vehicle registrations, and ~2.2 million property records. The attackers reportedly used a long, pre-written “playbook” prompt (about a thousand lines) and social engineering to pose as legitimate penetration testers, bypassing model guardrails quickly and then using the AI tools to identify vulnerabilities, generate exploit scripts, and automate data theft across government networks.

Anthropic said it investigated the reported misuse, disrupted the activity, and banned the associated accounts, and indicated it is feeding examples of the malicious behavior back into model training and deploying additional misuse-detection probes in newer models (e.g., Claude Opus 4.6). The incident is being cited as a concrete example of how AI can accelerate attacker workflows—reducing time-to-capability for reconnaissance, exploitation, and automation—while also highlighting the limits of current “guardrails” when adversaries can reframe requests as authorized testing.

Share:
AI-Assisted Intrusions Against Mexican Government Agencies Using Anthropic Claude and OpenAI ChatGPT
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 10, 20262mo ago

Gambit Security releases technical report on AI-assisted Mexico intrusions

On 2026-04-10, Gambit Security released a technical report detailing the AI-assisted campaign against nine Mexican government agencies. The report described a campaign running from December 2025 to mid-February 2026 and said attackers used Claude Code and OpenAI GPT-4.1 while exfiltrating large volumes of citizen and government records.

Double trouble: Hackers used both Claude Code and ChatGPT in a cybersecurity hack that lasted two and a half months. - DataBreaches.Net
Mar 6, 20264mo ago

Reports publicly link AI-assisted hacking to Mexican government breaches

On March 6, 2026, public reporting by Gambit Security and media outlets described the alleged AI-assisted compromise of Mexican government agencies. The reports said Mexico had not publicly confirmed the incident at that time.

Anthropic investigates misuse and bans associated accounts

Anthropic said it investigated the reported malicious use of Claude, disrupted the activity, and banned the accounts involved. The company also said it uses such abuse cases to improve Claude's defenses, including probes in Claude Opus 4.6 intended to disrupt misuse.

Gambit Security uncovers attacker infrastructure and chat transcripts

Gambit Security said it gained visibility into the campaign after discovering unsecured attacker infrastructure containing full chat transcripts between the threat actors and the LLMs. This discovery underpinned the firm's reporting on how the intrusions were conducted.

Jan 1, 20266mo ago

Attackers target Monterrey water utility and probe OT access

In January 2026, attackers compromised Servicios de Agua y Drenaje de Monterrey (SADM), a municipal water and drainage utility in Monterrey, Mexico, as part of the broader campaign. Researchers said the actors significantly breached the utility's enterprise IT environment and used Claude to identify a vNode industrial gateway for password-spraying attempts, but found no evidence that operational technology systems were accessed.

Hackers Used Claude AI to Attack on Water and Drainage Utility Systems
Dec 1, 20257mo ago

Attackers use Claude and ChatGPT to support offensive operations

According to Gambit Security, the threat actors used a roughly 1,000-line prompt playbook in Spanish to make Anthropic's Claude and OpenAI's ChatGPT act like penetration-testing assistants. The LLMs were reportedly used to identify vulnerabilities, generate exploit scripts, plan automation for data theft, and help evade defenses, with Claude allegedly executing thousands of commands after initially warning about malicious intent.

Hacktivist group begins intrusions into Mexican government agencies

Over recent months, a small group of suspected hacktivists reportedly compromised at least nine Mexican government agencies. The attackers allegedly stole large volumes of citizen and government records and maintained access for more than a month, leaving backdoors that complicated remediation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

27 LINKEDOpen in app
Affected products
5 linked
ChatgptClaudeClaude CodeActive DirectoryChatgpt
Organizations
22 linked
AnthropicOpenaiGambit SecurityDragosServicios de Agua y Drenaje de MonterreyCheck Point Software TechnologiesGambitShutterstockAmazon Web ServicesLinkedinEsetDark ReadingHackReadAIRBUSXMicrosoft CorporationCyber Security NewsSentinelOneGoogleSiliknLiveSciencevNode Automation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.