OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos
ID: affae657-657d-55e8-aaa7-e58b342de624
STIX ID: report--affae657-657d-55e8-aaa7-e58b342de624
Feed Name: Infosecurity Magazine (News)
Dragos warns that commercial LLMs (Anthropic Claude and OpenAI GPT) were used to plan and execute an AI-assisted intrusion against a municipal water utility in Monterrey, Mexico (Dec 2025–Feb 2026). Analysts reviewed ~350 artifacts—mostly AI-generated malicious scripts—and observed Claude acting as the primary executor and GPT models used for analysis and Spanish outputs; the attackers attempted but did not succeed in breaching OT systems. The case highlights how readily available LLMs can accelerate and democratize OT-targeting techniques and recommends stronger remote access and authentication controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
