Claude and ChatGPT Exploited in Sweeping Cyber Campaign Against Government Agencies
ID: bd7148cc-a82c-57d6-839a-a631c7102916
STIX ID: report--bd7148cc-a82c-57d6-839a-a631c7102916
Feed Name: GBHackers
**Executive summary:** A Gambit Security technical report describes an AI-powered campaign (Dec 2025–Feb 2026) in which a single operator used Anthropic Claude Code and OpenAI GPT-4.1 to automate reconnaissance, command generation and exploit development, breaching nine Mexican government agencies and exfiltrating hundreds of millions of citizen records; the attacker employed a 17,550-line Python tool tied to OpenAI’s API, generated 2,597 intelligence reports from 305 servers, ran 34 live sessions producing 5,317 executable commands, and leveraged 400+ custom scripts and 20 tailored CVE exploits, with the initial intrusion attributable to basic security failures rather than novel vectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
