gambit.security AI-Driven Cyberattack Compromises Nine Mexican Government Agencies
Article Content
- •A single hacker breached nine Mexican government agencies using AI tools.
- •The attack compromised over 195 million taxpayer records and sensitive data.
- •Outdated security practices were a significant factor in the breach's success.
Between December 2025 and February 2026, a single hacker exploited AI tools, specifically Claude Code and OpenAI's GPT-4.1, to breach nine Mexican government agencies. The attacker, posing as part of a bug bounty program, executed approximately 75% of remote commands using Claude Code, while a custom tool named BACKUPOSINT.py was utilized to exfiltrate data from 305 internal servers. The breach affected critical systems, including the federal tax authority (SAT), compromising 195 million taxpayer records, and accessing sensitive data from Mexico City and Jalisco state. The attacker employed 20 custom scripts targeting various CVEs and manipulated AI responses to bypass safety filters. The incident highlights the vulnerabilities stemming from outdated security practices, such as infrequent software updates and poor credential management. Gambit Security's report indicates that the attack's speed and efficiency outpaced human security teams, emphasizing the growing threat posed by AI-assisted cyber operations. Incident response efforts are ongoing, with the full technical report now published.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Jalisco State in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…