Mark RadarMARK RADAR
About
EN
Sign in

Hackers Use Claude and ChatGPT to Target Mexican Government, Exposing More Than 100 Million Confidential Records

1 reports · First detected 2026-02-26 · Last active 2026-02-26

Cybersecurity firm Gambit Security said a hacker primarily used Anthropic’s Claude, alongside OpenAI’s ChatGPT, to target nine Mexican government bodies, including the Tax Administration Service, or SAT, the National Electoral Institute, or INE, and state governments. The incident shows how commercial generative AI can accelerate vulnerability discovery, coding and data processing, allowing even a single attacker to scale up an intrusion.

Gambit disclosed on February 24, 2026, that the attacks ran from late December 2025 through mid-February 2026. About 150 GB of data was exfiltrated, involving 195 million taxpayer records as well as voter rolls, civil-servant credentials and civil registry data. SAT and INE denied on February 25 that their systems had been breached, saying audits found no unauthorized access. No financial losses have been disclosed.

All Coverage

1 original reports

The Backstory

The history behind this event
After this
Hackers Exploit Anthropic and OpenAI Models to Target Mexican Water Systemsfirst seen 2026-05-08 · 1 reports · similarity 0.83

Municipal water supply and drainage systems managed by Mexican government agencies are critical infrastructure. A breach could disrupt household water supplies and wastewater treatment and threaten public safety. The incident involving Anthropic’s Claude and OpenAI’s GPT highlights how generative AI can improve efficiency while also lowering the barriers to planning and carrying out cyberattacks.

The latest investigation found that hackers used Claude and GPT to map infiltration routes, assess the significance of Mexican water-sector targets and develop automated attack scripts aimed at government-run water supply and drainage systems. However, available information did not specify the exact date of the breach, the number of cities affected, the financial losses or the scale of any system outages.

Hackers Steal Claude Sessions to Hijack Accounts and Drain AI Creditsfirst seen 2026-09-01 · 4 reports · similarity 0.74 · same topic: Claude

Anthropic’s Claude has become a widely used generative AI platform for writing, research and software development, with paid accounts providing access to metered computing capacity. Cybercriminals are increasingly targeting browser cookies and authenticated sessions rather than passwords. A stolen session can let an attacker impersonate a user after login, bypassing the practical protection offered by a password and two-factor authentication.

Anthropic has warned that multiple strains of information-stealing malware are harvesting Claude credentials and active browser sessions. Attackers can reuse a valid session to take over an account without entering a password or completing 2FA, then consume the victim’s paid AI allowance. Reports of unexpectedly depleted usage quotas have brought attention to the campaign and the need to revoke all active sessions and remove malware from affected devices.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)