Gambit says one operator used Claude Code and GPT-4.1 in a campaign targeting nine Mexican government organizations
Gambit Security says a single operator used Claude Code and GPT-4.1 throughout a late-December 2025 to mid-February 2026 campaign targeting nine Mexican government organizations. The reported AI-assisted activity is detailed, but the extent of confirmed victim impact remains disputed.
The Reality Check
Context
Gambit’s later report says recovered forensic materials showed Claude Code and GPT-4.1 used as operational tools from late December 2025 through mid-February 2026. The report describes 1,088 logged prompts, 5,317 AI-executed commands across 34 sessions, more than 400 custom attack scripts, 20 tailored exploits, a 17,550-line Python tool, and 2,597 structured reports across 305 internal servers. Gambit estimates that Claude Code generated and executed about 75% of remote-command activity.
Those figures come from a private security firm’s account of recovered material. The public record does not include a complete, independently audited chain of custody for the underlying servers, logs, scripts, or alleged exfiltrated data. SAT and INE publicly disputed the reported impact on their systems. The separate Anthropic case shows that AI can support substantial cyber operations, but it is not evidence that this Mexican campaign achieved the same level of access or autonomy.
The strongest public finding concerns how AI was reportedly used; the weakest concerns the total scope of confirmed victim impact.
A high share of AI-generated commands is not the same as a high share of the operator’s decisions, and evidence of attempted intrusion is not automatically evidence of successful breach or exfiltration.
THE TAKEAWAY
Gambit’s report is meaningful evidence that a security firm identified a detailed AI-assisted intrusion workflow in recovered materials. It is not yet public proof that one person successfully breached all nine named organizations or stole the reported data volumes. The case should be treated as a disputed but important signal about the operational leverage of AI in cyberattacks.
Continue the Thread
AI in CyberattacksTracks evidence that AI systems can help plan, carry out, or scale real-world cyberattacks across increasing technical scope, autonomy, and impact.
Sources
A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report
Gambit Security
Used for: Campaign dates and preparation; three recovered servers; one-person assessment; nine-organization scope; Claude Code and GPT-4.1 roles; prompt, command, session, script, exploit, server, and report counts; 75% remote-command estimate; translated excerpts; published file indicators; disclosed evidence limits; and standard-control context.
Prevention has lost its edge. Resilience is the winning play.
Gambit Security
Used for: Initial 24 February 2026 public disclosure, the earlier one-month description, the original characterization of a small group rather than one operator, and notice that a later technical report would follow responsible disclosure.
Rechaza INE vulneración a sus bases de datos
Instituto Nacional Electoral
Used for: INE's denial of a security breach, unauthorized access, or exfiltration; its statement that no corroborated incident was found; and its criticism that no publicly verifiable forensic evidence had then been supplied.
Tarjeta informativa 6. Sobre el supuesto ciberataque a instituciones por medio de inteligencia artificial
Servicio de Administración Tributaria / Government of Mexico
Used for: SAT's statement that it reviewed logs for potentially related systems and found no illegitimate access or anomalous operational behavior.
Disrupting the first reported AI-orchestrated cyber espionage campaign
Anthropic
Used for: Previous frontier: Anthropic's high-confidence Chinese state-sponsored attribution, roughly 30 attempted targets, limited successful intrusions, extensive Claude Code execution, and continuing human decision points.
NIDS Commentary No. 434: Impact and countermeasures of scaling through AI misuse in advanced cyberattack campaigns
National Institute for Defense Studies / Japan Ministry of Defense
Used for: Independent strategic analysis of how AI could reduce human coordination constraints in advanced cyberattack campaigns, limits on current conclusions, and contemporaneous acknowledgment that named Mexican organizations disputed the reported impact.
Hacker Used Anthropic's Claude to Steal Mexican Data Trove
Bloomberg
Used for: Initial reporting; the 150 GB allegation; named organizations; Spanish-language prompts and safeguard behavior; institutional responses; statements from Anthropic and OpenAI about investigations, refusals, disruption, and account bans; and statements attributed to Gambit researchers.
Last checked Methodology 2.0.0