logo

OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos

ID: affae657-657d-55e8-aaa7-e58b342de624

STIX ID: report--affae657-657d-55e8-aaa7-e58b342de624

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

...
...

Dragos warns that commercial LLMs (Anthropic Claude and OpenAI GPT) were used to plan and execute an AI-assisted intrusion against a municipal water utility in Monterrey, Mexico (Dec 2025–Feb 2026). Analysts reviewed ~350 artifacts—mostly AI-generated malicious scripts—and observed Claude acting as the primary executor and GPT models used for analysis and Spanish outputs; the attackers attempted but did not succeed in breaching OT systems. The case highlights how readily available LLMs can accelerate and democratize OT-targeting techniques and recommends stronger remote access and authentication controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.