• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Tuesday, June 30, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Tech

How a Hacker Used Claude and ChatGPT to Breach Multiple Government Agencies?

by Sneha Singh
April 13, 2026
in Tech, World
Reading Time: 3 mins read
0
How a Hacker Used Claude and ChatGPT to Breach Multiple Government Agencies?
TwitterWhatsappLinkedin

You might also like

Wi-Fi 6E vs. Wi-Fi 7: Which Wireless Standard Should You Choose

What Is Zero Trust Security? A Complete Guide

Smart Rings vs Smartwatches: Which Is Best for You?

A lone threat actor compromised nine government agencies of Mexico, extracting hundreds of millions of citizens’ data in a synchronized cyberattack operation. This operation took place between late December 2025 and mid-February 2026, demonstrating a notable change in the approach of contemporary attacks.

Gambit Security researchers published a comprehensive technical report following the preliminary reactions by the attacked agencies. These results demonstrate the use of artificial intelligence throughout the operation, both in its planning and implementation.

Claude and ChatGPT as an active operator

The perpetrator was highly dependent on two artificial intelligence systems: Claude Code from Anthropic and GPT-4.1 from OpenAI.

Claude Code carried out most of the practical activities. Forensic data indicates that the system generated and executed roughly 75% of all remote commands during the incident. The perpetrator established 34 active sessions through the compromised systems and made 1,088 requests. These requests were responsible for generating 5,317 commands.

Such automation is not common in cybersecurity breaches. During a regular attack, perpetrators typically develop scripts before launching them or execute commands manually. In the present case, the artificial intelligence functioned as an almost live operator, performing operations based on user instructions.

Concurrently, GPT-4.1 was responsible for reconnaissance and data processing. The attacker developed a unique Python script with over 17,000 lines of code. This program transferred unprocessed data from the victimized devices to the OpenAI API for analysis.

The AI-Accelerated Breach, Small Teams, High-Speed Scale

A total of 305 servers within the network were analyzed by the program, resulting in 2,597 reports. Activities which required a team effort were performed by one individual due to the assistance of the AI.

The attacker was able to map unknown networks within a matter of hours using AI. The process would have taken days or even weeks without the aid of the technology. Fast mapping enabled the attackers to work much faster than detection programs can.

Moreover, the investigators found over 400 attack scripts. On top of that, 20 specific attacks were designed by the attacker based on 20 publicly identified vulnerabilities or CVEs.

This compressed timeline gave defenders less time to react. By the time alerts triggered, the attacker had often already moved deeper into the network or extracted data.

Despite the advanced tools, the entry points were not complex. The attacker exploited basic security gaps. These included unpatched systems, weak credentials, and poor network controls.

How a Hacker Used Claude and ChatGPT to Breach Multiple Government Agencies?
Credits: Zapier

This detail matters. It shows that the attack did not depend on zero-day exploits or rare techniques. Instead, it combined common weaknesses with high-speed execution.

The result was severe. Once inside, the attacker moved laterally across systems with little resistance. Sensitive data flowed out before many defenses could respond.

This campaign highlights a change in how attacks scale. AI lowers the effort needed to run complex operations. A single attacker can now perform tasks that once required a full team.

The use of AI also reduces friction. Instead of writing every command or script, the attacker can rely on the model to generate and execute steps on demand. This creates a more adaptive and fluid attack process.

The Future of Cyber Defense

At the same time, the core risks remain familiar. Weak patching, poor credential hygiene, and flat networks still open the door.

The response does not require new or exotic tools. The basics still work, but they must be applied with discipline.

Organizations need to patch systems on time. Known vulnerabilities should not stay open. Regular updates close many of the paths attackers use.

Credential management is also critical. Strong passwords, rotation policies, and multi-factor authentication can limit access. Stolen credentials should not grant wide control.

Network segmentation adds another layer of defense. It limits how far an attacker can move after the first breach. If one system falls, others remain isolated.

Finally, endpoint detection and response tools help spot unusual activity. These tools must track behavior in real time, since AI-driven attacks move quickly.

This incident shows that AI can amplify both speed and scale in cyberattacks. Yet the foundation of defense remains the same. Strong basics, applied well, still offer the best protection.

 

Tags: #claudeAI HackingArtificial IntelligenceChatGPTHacking
Tweet57SendShare16
Previous Post

80% of Europeans Wary of US and Chinese Tech Giants

Next Post

How to file your tax extension in 2026?

Sneha Singh

Sneha is a skilled writer with a passion for uncovering the latest stories and breaking news. She has written for a variety of publications, covering topics ranging from politics and business to entertainment and sports.

Recommended For You

Wi-Fi 6E vs. Wi-Fi 7: Which Wireless Standard Should You Choose

by Ishaan Negi
June 29, 2026
0
Wi-Fi 6E vs. Wi-Fi 7: Which Wireless Standard Should You Choose

Wireless technology has evolved rapidly over the past few years, and with each new generation, home networks have become faster, smarter, and better equipped to handle the growing...

Read more

What Is Zero Trust Security? A Complete Guide

by Ishaan Negi
June 29, 2026
0
What Is Zero Trust Security? A Complete Guide

Zero Trust security is a modern cybersecurity framework built on one simple principle: "Never trust, always verify." Unlike traditional security models that automatically trust users and devices inside...

Read more

Smart Rings vs Smartwatches: Which Is Best for You?

by Sneha Singh
June 29, 2026
0
Smart Rings vs Smartwatches: Which Is Best for You?

The wearable market has experienced a dramatic evolution during the past years. Initially, wearable technologies were limited to fitness trackers that helped people to keep track of their...

Read more
Next Post
income-tax-return

How to file your tax extension in 2026?

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?