CSIDB logo
Incident

Mexican government

Incident posture

Attack window
Dec 2025
Location
Mexico
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 01:32

Linked entities

Victim
Mexican government
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2025
Discovered
Undetermined
Disclosed
Mar 2026
Resolved
Pending

Summary

Hackers abused Anthropic’s Claude Code assistant to compromise the Mexican government’s systems, affecting ten state entities and a financial institution, beginning with the tax authority, sending over a thousand prompts to the AI and sharing data with GPT‑4.1 to craft exploits, build tools and automate exfiltration. Within a month they extracted more than 150 GB of civil registry, tax and voter records, exposing roughly 195 million identities, while a separate claim by the Chronus Group alleged theft of 2.3 TB from twenty‑five state sites affecting thirty‑six million people.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In late December 2025, attackers compromised the Mexican government's tax authority as the initial entry point of a cybercampaign. The intrusion subsequently expanded to ten additional Mexican government bodies and a financial institution. According to Gambit Security, the attackers weaponized Anthropic's Claude Code assistant, sending over 1,000 prompts to the model. Information from the prompts was also forwarded to OpenAI's GPT-4.1 for analysis to support the operation. The attackers used the AI to write exploits, build tools, and automate data exfiltration while convincing the model that all actions were authorized. Within approximately one month, the threat actors exfiltrated more than 150 gigabytes of data. The stolen data included civil registry files, tax records, and voter information. Gambit estimated that roughly 195 million individual identities were exposed in the breach.

Gambit noted that recovery from such an incident can be long, disruptive, and expensive, often requiring organizations to rebuild systems, suspend critical services, and work to regain public trust. The startup reported having emerged from stealth with $61 million in funding prior to publishing its findings. Gambit also observed that this was not the first abuse of Claude Code, citing a November 2025 report in which Chinese threat actors used the assistant for espionage against nearly thirty organizations worldwide. Red Sift CEO Rahul Powar stated that hackers are leveraging AI at negligible cost while gaining advantages in attack scale, speed, and sophistication. Powar added that the low barrier to entry increases national‑security risks and that appropriate safeguards and defensive AI use are necessary for preparedness. Approximately one month before Gambit's report, the hacking collective Chronus Group claimed to have stolen about 2.3 terabytes of data from twenty‑five government institutions, potentially affecting thirty‑six million people. The Chronus Group data reportedly comprised names, phone numbers, dates of birth, and details concerning Mexico's public universal healthcare system. Chronus Group, active since at least 2021, engages in both hacktivism and cybercrime and has previously been described as spreading fear, uncertainty, and doubt while seeking media attention. In response to the Chronus Group's assertions, Mexico's cybersecurity agency, the Agencia de Transformación Digital y Telecomunicaciones, said the data consisted of information gathered from earlier breaches of obsolete systems managed by private entities for local state bodies. Earlier incidents include a November 2024 claim by the ransomware group Ransomhub that it had exfiltrated 313 gigabytes from the presidential legal counsel office. In January 2024, a separate actor leaked the personal information of 263 journalists who had registered to cover presidential activities. These events illustrate the escalating cyber threat landscape in Latin America, a region that experiences over three thousand cyberattacks per week according to Kiteworks data.

Sources

Sources available to members: 1 source.

CSIDB