Skip to main content

Gambit says one operator used Claude Code and GPT-4.1 in a campaign targeting nine Mexican government organizations

Gambit Security says a single operator used Claude Code and GPT-4.1 throughout a late-December 2025 to mid-February 2026 campaign targeting nine Mexican government organizations. The reported AI-assisted activity is detailed, but the extent of confirmed victim impact remains disputed.

The Reality Check

The public record does not independently establish that all nine organizations were breached or that the reported data volumes were exfiltrated. SAT says its log review found no illegitimate access or anomalous behavior, while INE says it found no breach, unauthorized access, or corroborated exfiltration. Gambit’s initial disclosure also described a small group before its later report attributed the campaign to one operator.

Context

Gambit’s later report says recovered forensic materials showed Claude Code and GPT-4.1 used as operational tools from late December 2025 through mid-February 2026. The report describes 1,088 logged prompts, 5,317 AI-executed commands across 34 sessions, more than 400 custom attack scripts, 20 tailored exploits, a 17,550-line Python tool, and 2,597 structured reports across 305 internal servers. Gambit estimates that Claude Code generated and executed about 75% of remote-command activity.

Those figures come from a private security firm’s account of recovered material. The public record does not include a complete, independently audited chain of custody for the underlying servers, logs, scripts, or alleged exfiltrated data. SAT and INE publicly disputed the reported impact on their systems. The separate Anthropic case shows that AI can support substantial cyber operations, but it is not evidence that this Mexican campaign achieved the same level of access or autonomy.

The strongest public finding concerns how AI was reportedly used; the weakest concerns the total scope of confirmed victim impact.

A high share of AI-generated commands is not the same as a high share of the operator’s decisions, and evidence of attempted intrusion is not automatically evidence of successful breach or exfiltration.

THE TAKEAWAY

Gambit’s report is meaningful evidence that a security firm identified a detailed AI-assisted intrusion workflow in recovered materials. It is not yet public proof that one person successfully breached all nine named organizations or stole the reported data volumes. The case should be treated as a disputed but important signal about the operational leverage of AI in cyberattacks.

Continue the Thread

AI in Cyberattacks

Tracks evidence that AI systems can help plan, carry out, or scale real-world cyberattacks across increasing technical scope, autonomy, and impact.

Sources

A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report

Gambit Security

Primary EvidenceResearcher / Organization Claim · Technical Artifact

Used for: Campaign dates and preparation; three recovered servers; one-person assessment; nine-organization scope; Claude Code and GPT-4.1 roles; prompt, command, session, script, exploit, server, and report counts; 75% remote-command estimate; translated excerpts; published file indicators; disclosed evidence limits; and standard-control context.

Prevention has lost its edge. Resilience is the winning play.

Gambit Security

Primary EvidenceResearcher / Organization Claim

Used for: Initial 24 February 2026 public disclosure, the earlier one-month description, the original characterization of a small group rather than one operator, and notice that a later technical report would follow responsible disclosure.

Rechaza INE vulneración a sus bases de datos

Instituto Nacional Electoral

Official RecordOfficial Claim

Used for: INE's denial of a security breach, unauthorized access, or exfiltration; its statement that no corroborated incident was found; and its criticism that no publicly verifiable forensic evidence had then been supplied.

Hacker Used Anthropic's Claude to Steal Mexican Data Trove

Bloomberg

Media ReportMedia Report

Used for: Initial reporting; the 150 GB allegation; named organizations; Spanish-language prompts and safeguard behavior; institutional responses; statements from Anthropic and OpenAI about investigations, refusals, disruption, and account bans; and statements attributed to Gambit researchers.

Last checked Methodology 2.0.0