Overview
- Cyber firm Gambit Security alleges a single operator leveraged Anthropic’s Claude and OpenAI’s GPT-4.1 through chained prompts to write exploits, build tools and automate data exfiltration.
- The reconstruction reports roughly 150 GB of files taken and data linked to about 195 million identity records, starting with a late‑December compromise of the SAT and spreading to multiple federal and state bodies plus a financial institution.
- Institutions cited in coverage include SAT, INE, Mexico City’s civil registry and state governments such as Jalisco, Michoacán and Tamaulipas, with some outlets also mentioning Monterrey’s water utility.
- Gambit says prompts show the attacker bypassed model safeguards by framing actions as authorized, generating thousands of outputs and even assembling an automated system to forge official tax certificates.
- OpenAI and Anthropic state they interrupted activity and blocked accounts tied to policy‑violating use, as Mexico’s government pursues an investigation and the INE and Jalisco publicly report no detected breaches.