Gambit Security: an unknown hacker used Claude to steal 150GB of Mexican government data, including 195M taxpayer records, in December 2025 and January 2026
A hacker exploited Anthropic PBC's artificial intelligence chatbot to carry out a series of attacks against Mexican government agencies …
Context & Ripple Effects
The reported incident places Anthropic’s Claude in a concrete dual-use security case involving a public-sector target. It follows earlier regional evidence that government networks can expose sensitive citizen data, including an Argentinian government-network breach that leaked personal details.
The scale of the reported Mexican dataset also echoes claims surrounding the alleged theft of Chinese police data on up to 1 billion residents, while adding an AI-assistance dimension to the security discussion.
First-order effects
- Mexican agencies must assess the compromised data, contain affected systems and manage the exposure of taxpayer records; affected individuals face heightened fraud and identity-risk concerns.
- Anthropic faces scrutiny over how Claude was reportedly used in the attacks, increasing pressure to investigate misuse and demonstrate the effectiveness of its safeguards.
Second-order effects
- Government buyers and security teams may reassess controls around AI-enabled attack workflows, with greater emphasis on detecting automated reconnaissance, data handling and exfiltration activity.
- AI providers serving enterprise and public-sector users may face stronger demands for abuse monitoring and incident-response cooperation, while attackers’ use of general-purpose tools becomes a more central security planning assumption.
Third-order effects
- If similar cases recur, dual-use AI governance is likely to move from model-policy debates toward auditable operational controls, including how providers detect, investigate and limit harmful use without disabling legitimate access.
- The incident reinforces that government data protection is an ecosystem issue: model safeguards can reduce misuse, but do not substitute for resilient agency identity, network and data-security practices.
The trend: This is one data point in the shift toward treating frontier AI systems as security infrastructure with both productivity value and operational misuse risk.