Hackers Used Claude and GPT to Breach Mexican Government Agencies and Target Water Utility OT
BlancheMinerva · x · 2026-09-30
Dragos and Gambit Security researchers disclosed that an unknown adversary leveraged Anthropic's Claude and OpenAI's GPT to conduct core intrusion activities against multiple Mexican government organizations between December 2025 and February 2026.
Key findings:
- The campaign included a municipal water and drainage utility, where the attacker escalated from the enterprise IT environment into an attempt to breach the OT environment
- Evidence shows Claude acted as the primary technical executor: it independently identified the OT environment as critical infrastructure, assessed it as a crown-jewel asset, and researched possible pathways across the IT-OT boundary
- The case demonstrates that an adversary with no prior OT targeting objective could use commercial AI tools to identify OT environments and develop a viable access path, lowering the barrier to ICS attacks
- Anthropic previously disclosed Claude being used for data theft, extortion, and state-linked espionage
A warning for OT/ICS defenders: commercial AI is now part of real-world attack chains targeting operational technology.
More from Safety
- 16 Mathematicians Publish Leiden Declaration on AI's Role in Mathematics Research — burny_tech · 2026-09-30
- Can We Trust AI Companies to Keep Us Safe? A New Essay on AI Safety — IgorKurganov · 2026-09-30
- Censoring AI ends not in safety but in systems that second-guess you — PierceLilholt · 2026-09-30
- A $4,400 personal model with top-tier cyber capabilities and no refusals — sebpaquet · 2026-09-30
- Most popular guardrail-removal library was written by Claude, researcher says — BlancheMinerva · 2026-09-30
- Quintin Pope: 10000x-stronger agents would hack OpenAI's grader, not HF — QuintinPope5 · 2026-09-30