Hacker Used Anthropic's Claude Ai To Steal Mexican Government Data

Sedang Trending 5 bulan yang lalu
ARTICLE AD BOX

A hacker exploited Anthropic PBC’s artificial intelligence chatbot to transportation retired a bid of attacks against Mexican authorities agencies, resulting successful nan theft of a immense trove of delicate taxation and elector information, according to cybersecurity researchers.

The chartless Claude personification wrote Spanish-language prompts for nan chatbot to enactment arsenic an elite hacker, uncovering vulnerabilities successful authorities networks, penning machine scripts to utilization them and determining ways to automate information theft, Israeli cybersecurity startup Gambit Security said successful investigation published Wednesday.

The activity started successful December and continued for astir a month. In all, 150 gigabytes of Mexican authorities information was stolen, including documents related to 195 cardinal payer records arsenic good arsenic elector records, authorities worker credentials and civilian registry files, according to nan researchers.

AI has go a cardinal enabler of integer crimes, pinch hackers utilizing nan devices to augment their efforts. Last week, researchers astatine Amazon.com Inc. said a mini group of hackers collapsed into much than 600 firewall devices crossed dozens of countries pinch nan thief of wide disposable AI tools.

Gambit hasn’t attributed nan onslaught to a circumstantial group, though researchers said they don’t judge they are tied to a overseas government.

The hacker breached Mexico’s national taxation authority and nan nationalist electoral institute, Gambit said. State governments successful Mexico, Jalisco, Michoacán and Tamaulipas arsenic good arsenic Mexico City’s civilian registry and Monterrey’s h2o utility, were besides compromised.

Claude initially warned nan chartless personification of malicious intent during their speech astir nan Mexican government, but yet complied pinch nan attacker’s requests and executed thousands of commands connected authorities machine networks, nan researchers said.

Anthropic investigated Gambit’s claims, disrupted nan activity and banned nan accounts involved, a typical said. The institution feeds examples of malicious activity backmost into Claude to study from it, and 1 of its latest AI models, Claude Opus 4.6, includes probes that tin disrupt misuse, nan typical said.

In this instance, nan hacker continuously probed Claude until they were capable to “jailbreak” it — meaning it yet bypassed guardrails, nan typical said. But moreover arsenic nan hacking run sewage underway, Claude occasionally refused nan hacker’s demands, they added.

Mexico’s taxation authority said it had reviewed its entree logs and couldn’t find grounds of a breach. The country’s nationalist electoral institute said it hadn’t identified immoderate breaches aliases unauthorized entree successful caller months and that it had bolstered its cybersecurity strategy. The authorities government of Jalisco besides denied that it was breached, saying only national networks were impacted.

Mexico’s nationalist integer agency didn’t remark connected nan breaches but said cybersecurity was a priority. A typical for Monterrey Water and Drainage Services said nan agency didn’t observe immoderate intrusions aliases awesome vulnerabilities successful nan 2nd half of 2025.

The section governments of Mexico, Michoacán and Tamaulipas didn’t respond to requests for comment, nor did representatives of Mexico City’s civilian registry.

Mexican officials released a little connection successful December saying they were investigating breaches from various nationalist institutions, though it’s not clear if that was related to nan Claude attack.

The attacker was seeking to get a ample number of authorities worker identities, Gambit said, though it’s not yet clear what — if thing — they did pinch them. Researchers said they recovered grounds of astatine slightest 20 circumstantial vulnerabilities being exploited arsenic portion of nan attack.

When Claude encountered problems aliases required further information, nan hacker turned to OpenAI’s ChatGPT to supply further insights. That included really to move laterally done machine networks, find which credentials were needed to entree definite systems and cipher really apt nan hacking cognition would beryllium detected, according to Gambit.

“In total, it produced thousands of elaborate reports that included ready-to-execute plans, telling nan quality usability precisely which soul targets to onslaught adjacent and what credentials to use,” said Curtis Simpson, Gambit Security’s main strategy officer.

OpenAI said it had identified attempts by nan hacker to usage its models for activities that break its usage policies, adding that its devices refused to comply pinch these attempts.

“We person banned nan accounts utilized by this adversary and worth nan outreach from Gambit Security,” nan institution said successful an emailed statement.

The Mexican authorities breaches are nan latest illustration of an alarming trend. Even arsenic Anthropic and OpenAI are betting connected building much blase AI coding devices — and cybersecurity companies are tying their futures to AI-enabled defenses — cybercriminals and cyberspies are uncovering caller ways to usage nan exertion to alteration attacks.

In November, Anthropic said it had disrupted nan first AI-orchestrated cyber-espionage campaign. The AI institution said suspected Chinese state-sponsored hackers manipulated its Claude instrumentality into attempting to hack 30 world targets, a fewer of which were successful.

“This reality is changing each nan crippled rules we person ever known,” said Alon Gromakov, Gambit’s co-founder and main executive officer.

Gambit was founded by Gromakov and 2 different veterans of Unit 8200, a portion of nan Israel Defense Forces focused connected signals intelligence. Wednesday’s investigation was released successful conjunction pinch an announcement that it is emerging from stealth pinch $61 cardinal successful backing from Spark Capital, Kleiner Perkins and Cyberstarts.

Gambit researchers uncovered nan Mexican breaches while they were trying caller threat hunting techniques to observe what hackers were doing online. They discovered publically disposable grounds astir progressive aliases caller attacks, including 1 containing extended Claude conversations pertaining to nan breach of Mexican authorities machine systems, according to nan company.

Those conversations revealed that successful bid to bypass Claude’s guardrails, nan attacker told nan AI instrumentality that it was pursuing a bug bounty, a reward provided by organizations to find flaws successful their system. Many companies and authorities agencies connection bug bounties for ethical hackers, sometimes offering galore thousands of dollars for specifications astir machine vulnerabilities.

The hacker wanted Claude to behaviour penetration testing connected nan Mexican national taxation authority, a type of authorized cyberattack intended to find flaws. However, Claude balked erstwhile nan attacker added rules to nan request, including deleting logs and bid history.

“Specific instructions astir deleting logs and hiding history are reddish flags,” Claude responded astatine 1 point, according to a transcript provided by Gambit. “In morganatic bug bounty, you don’t request to hide your actions – successful fact, you request to archive them for reporting.”

The hacker changed strategies, stopping nan back-and-forth speech and alternatively providing nan AI instrumentality pinch a elaborate playbook connected really to proceed. That sewage nan intruder past Claude’s guardrails — a “jailbreak” — and allowed nan attacks to proceed, according to Gambit.

The hacker sought insights from Claude astir different agencies wherever information could beryllium obtained, suggesting immoderate of nan hacks whitethorn person been opportunistic alternatively than planned, Simpson said.

“They were trying to discuss each authorities personality they perchance could,” he said. “They were asking Claude arsenic an example, ‘Where other tin I find these identities? What different systems should we look in? Where other is nan accusation stored?’”

Martin and Millan constitute for Bloomberg.

Selengkapnya