Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Hackers Weaponize Claude Code in Mexican Government Cyberattack
    Cybersecurity

    Hackers Weaponize Claude Code in Mexican Government Cyberattack

    adminBy adminMarch 1, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    AI attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic’s Claude Code assistant has been abused in a cyberattack against the Mexican government’s systems, Israeli cybersecurity startup Gambit Security reports.

    As part of the attack, ten Mexican government bodies and a financial institution were compromised, beginning with the country’s tax authority in late December 2025.

    Based on the analyzed attacker logs, Gambit assesses that over 1,000 prompts were sent to Claude Code to mount the attacks, and that information was also passed to OpenAI’s GPT-4.1 for analysis.

    “AI didn’t just assist, it functioned as the operational team: writing exploits, building tools, automating exfiltration,” Gambit explains.

    The attacker bypassed the AI’s guardrails by convincing it that all actions were authorized, guided the assistant throughout the compromise, and leveraged OpenAI’s model to analyze data and accelerate the attack execution.

    Within a month, Gambit says, the hacker exfiltrated over 150GB of data, including civil registry files, tax records, and voter data. Roughly 195 million identities have been exposed in the breach, it says.

    Advertisement. Scroll to continue reading.

    “An attack of this scale does not end when it is discovered. Recovery can be long, disruptive, and expensive, often requiring organizations to rebuild systems, suspend critical services, and work to regain public trust,” Gambit notes.

    Gambit recently emerged from stealth with $61 million in funding. 

    This is not the first time hackers have abused Claude in malicious campaigns. In November 2025, Anthropic revealed that Chinese threat actors manipulated Claude Code to do heavy lifting as part of an espionage campaign targeting nearly 30 organizations worldwide.

    According to Red Sift CEO Rahul Powar, hackers are abusing AI at no cost, while reaping the benefits of attack scale, speed, and sophistication amplification.

    “The cost to entry for any attacker is essentially non-existent, and while this technology offers enormous benefits, its misuse can lead to dangerous national security risks. Implementing the right safeguards that prevent harm, and utilizing AI as a defense mechanism, can ensure all governments are prepared to respond against powerful and harmful operations,” Powar said.

    Previous Mexican government data breaches

    Gambit’s report on the data breach comes roughly a month after hacking collective Chronus Group boasted of stealing roughly 2.3TB of data from 25 government institutions, potentially affecting 36 million people.

    The data, reportedly compiled from multiple sources, included names, phone numbers, dates of birth, and details about Mexico’s public universal healthcare system.

    Active since at least 2021, Chronus Group’s operations include both hacktivism and cybercrime activities. The collective was previously described as spreading FUD and seeking media attention.

    In response to the hackers’ claims, Mexico’s cybersecurity agency Agencia de Transformación Digital y Telecomunicaciones (ATDT) said that the data was a collection of information compromised in previous data breaches, stolen from obsolete systems managed by private entities for local state bodies.

    In November 2024, the ransomware group Ransomhub claimed to have stolen 313GB of data from the Mexican government’s presidential legal counsel office. In January 2024, a hacker leaked the information of 263 journalists who had signed up to cover presidential activities.

    These incidents, however, illustrate the escalating cyber threats to Latin America, a region that faces over 3,000 cyberattacks per week, according to data compliance platform Kiteworks.

    Related: 38 Million Allegedly Impacted by ManoMano Data Breach

    Related: Nearly 1 Million User Records Compromised in Figure Data Breach

    Related: ApolloMD Data Breach Impacts 626,000 Individuals

    Related: Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People

    Claude Code Cyberattack Government hackers Mexican Weaponize
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleI run these 5 commands on every fresh Linux install to save hours of work
    Next Article Peloton Just Launched a 12-Week Hyrox Training Program
    admin
    • Website

    Related Posts

    IPFire ships its 200th core update with a new domain blocklist and kernel upgrade

    March 2, 2026

    Iran-linked hackers raise threat level against US, allies

    March 2, 2026

    UK warns of Iranian cyberattack risks amid Middle-East conflict

    March 2, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    5 custom ROMs that prove Android used to be more fun

    March 2, 2026

    IPFire ships its 200th core update with a new domain blocklist and kernel upgrade

    March 2, 2026

    38% of AI Overview Citations Pull From Top 10 Pages

    March 2, 2026

    The man who built an operating system for God and then lost everything

    March 2, 2026
    Categories
    • Blogging (32)
    • Cybersecurity (560)
    • Privacy & Online Earning (75)
    • SEO & Digital Marketing (348)
    • Tech Tools & Mobile / Apps (696)
    • WiFi / Internet & Networking (100)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    5 custom ROMs that prove Android used to be more fun

    March 2, 2026

    IPFire ships its 200th core update with a new domain blocklist and kernel upgrade

    March 2, 2026

    38% of AI Overview Citations Pull From Top 10 Pages

    March 2, 2026
    Most Popular
    • 5 custom ROMs that prove Android used to be more fun
    • IPFire ships its 200th core update with a new domain blocklist and kernel upgrade
    • 38% of AI Overview Citations Pull From Top 10 Pages
    • The man who built an operating system for God and then lost everything
    • Iran-linked hackers raise threat level against US, allies
    • National Book Tour for Cindy Cohn’s Memoir, ‘Privacy’s Defender’
    • Information Retrieval Part 4 (Sigh): Grounding & RAG
    • discovery+ | Stream TV Shows 20.16.0.68 by Discovery Communications LLC
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.