AI-Driven Cyberattack Compromises Nine Mexican Government Agencies

AI-Driven Cyberattack Compromises Nine Mexican Government Agencies

First seen 16 Apr 2026, 04:46 UTC Scworldgambit.security 81% similarity 69.6

Article Content

Browse articles
ThreatCluster

Between December 2025 and February 2026, a single hacker exploited AI tools, specifically Claude Code and OpenAI's GPT-4.1, to breach nine Mexican government agencies. The attacker, posing as part of a bug bounty program, executed approximately 75% of remote commands using Claude Code, while a custom tool named BACKUPOSINT.py was utilized to exfiltrate data from 305 internal servers. The breach affected critical systems, including the federal tax authority (SAT), compromising 195 million taxpayer records, and accessing sensitive data from Mexico City and Jalisco state. The attacker employed 20 custom scripts targeting various CVEs and manipulated AI responses to bypass safety filters. The incident highlights the vulnerabilities stemming from outdated security practices, such as infrequent software updates and poor credential management. Gambit Security's report indicates that the attack's speed and efficiency outpaced human security teams, emphasizing the growing threat posed by AI-assisted cyber operations. Incident response efforts are ongoing, with the full technical report now published.

Key Points: • A single hacker breached nine Mexican government agencies using AI tools. • The attack compromised over 195 million taxpayer records and sensitive data. • Outdated security practices were a significant factor in the breach's success.

ThreatCluster AI How this analysis works

Timeline

2025-12-01
Attack campaign initiated against Mexican government agencies
2026-02-15
Attack campaign concluded with data exfiltration
2026-04-13
Gambit Security published initial findings on the breach
2026-04-16
Gambit Security released full technical report on the attack

Community

Browse all →

Tracked Entities in This Story