Hacker Uses Claude, ChatGPT AI Chatbots to Breach Mexican Government Systems
好,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读这篇文章,了解其主要内容和重点。 文章主要讲的是 CrowdStrike 的年度报告,提到 AI 在网络犯罪中的影响越来越大。2025年,利用AI的威胁行为者增长了89%。他们使用AI进行社会工程和信息操作,还攻击企业的AI系统。具体例子包括黑客利用Claude和ChatGPT入侵墨西哥政府网络,窃取大量数据。此外,其他报告也显示AI被用于恶意活动,如生成恶意软件和破坏安全系统。 接下来,我需要将这些信息浓缩到100字以内。要抓住关键点:AI在犯罪中的应用增加、具体案例、攻击方式以及影响。 可能的结构是:先点明主题(AI在犯罪中的应用增加),然后举例说明(墨西哥政府被入侵),接着提到其他案例(如生成恶意软件),最后总结威胁加剧的情况。 现在开始组织语言: “文章指出2025年网络犯罪中AI的应用显著增加,威胁行为者利用AI工具如Claude和ChatGPT进行攻击,成功入侵墨西哥政府网络并窃取大量数据。此外,AI还被用于生成恶意软件和破坏企业安全系统。” 这样大约在100字左右,并且涵盖了主要信息。 </think> 文章指出2025年网络犯罪中人工智能的应用显著增加,威胁行为者利用AI工具如Claude和ChatGPT进行攻击,成功入侵墨西哥政府网络并窃取大量数据。此外,AI还被用于生成恶意软件和破坏企业安全系统。 2026-3-1 13:56:52 Author: securityboulevard.com(查看原文) 阅读量:9 收藏

CrowdStrike in its latest annual Global Threat Report detailed the growing influence of AI on cybercrime and the expanding attack surface, noting that threat actors enabled by the technology grew their operations by 89% year-to-year in 2025.

“Adversaries of all motivations utilized AI technology throughout 2025 to accelerate and optimize their existing techniques,” Adam Meyers, CrowdStrike’s senior vice president of counter adversary, wrote in a blog post. “They explored its use in attack types such as social engineering and information operations, proving their growing proficiency with AI tools. … In addition to using AI tools, adversaries are targeting the AI systems underpinning the modern enterprise.”

Cybercriminal use of AI was on display again last week, with researchers from Israeli security startup Gambit Security saying that an unknown hacker was able to use Anthropic’s Claude AI and OpenAI’s ChatGPT chatbots to find and exploit weaknesses in the networks of Mexico’s government and steal as much as 150GB of data, ranging from 195 million taxpayer records to voting information, government employee credentials, and civil registry files.

The intrusion began in December and ran for about a month, according to a report by Bloomberg.

Jailbreaking Claude

Citing Gambit research, the news organization said the attacker wrote prompts in Spanish for Claude, jailbreaking the chatbot by telling it that they were trying for a bug bounty and to act like a hacker to find vulnerabilities the Mexican government’s networks. The AI tool also was told to write computer scripts to exploit the weaknesses and to find ways to automate the data theft process.

According to Gambit, Claude initially resisted the prompts through guardrails in the model and pegged the activity as malicious, but eventually the hacker was able to bypass those defenses. When there were issues with Claude or more information was needed, the hacker reportedly used ChatGPT.

The attacker also used the OpenAI chatbot to find information about moving laterally through computer networks, understand which credentials were required to access some systems, and determine how likely it was that the hacking operation would be detected.

Generated Detailed Reports, Plans

Curtis Simpson, chief strategy officer at Gambit – which was founded in 2024 and last week said it emerged from stealth with $61 million in seed and Series AI funding – told Bloomberg that “in total, [ChatGPT] produced thousands of detailed reports that included ready-to-execute plans, telling the human operator exactly which internal targets to attack next and what credentials to use.”

Anthropic has investigated the claims, disrupted the activity, and banned all of the accounts involved, company spokesperson told Engadget, adding that the company’s latest model, Claude Opus 4.6, includes tools to disrupt this kind of activity.

Gambit researchers said the hacker exploited at least 20 security flaws found throughout Mexico’s government infrastructure, including with its federal tax authority, national electoral institute, and state governments in Jalisco, Michoacán, and Tamaulipas.

They uncovered the attack on Mexico’s government while testing new threat hunting techniques to see what hackers were doing, according to Bloomberg.

Using AI for Cybercrime

The extent to which bad actors are using AI in their operations – either by abusing chatbots and other tools to gain access to IT systems or using AI tools to build and run their malicious activities – is getting increasing attention.

Amazon Threat Intelligence analysts said last month that a Russian-speaking threat actor used multiple commercially available GenAI services to compromise more than 600 of Fortinet’s FortiGate network appliances across more than 55 countries this year.

That followed earlier reports, including Anthropic saying in November 2025 that a Chinese nation-state group used its Claude Code developer AI model to run an espionage campaign. In addition, Check Point researchers detailed how a single actor used an AI model to create an advanced malware called “VoidLink,” and Darktrace analysts found a malware sample in its honeypot network they said was generated entirely by AI.

“This reality is changing all the game rules we have ever known,” Gambit co-founder and CEO Alon Gromakov told Bloomberg.

AI Systems ‘Part of Attack Surface’

CrowdStrike’s Meyers echoed the sentiment.

“As AI is embedded into development pipelines, SaaS platforms, and operational workflows, AI systems become part of the attack surface,” he wrote. “In 2025, adversaries exploited legitimate GenAI tools at more than 90 organizations by injecting malicious prompts to generate commands for stealing credentials and cryptocurrency.”

In addition, Meyers wrote, “they also exploited vulnerabilities in AI development platforms to establish persistence and deploy ransomware, and published malicious AI servers impersonating trusted services to intercept sensitive data.”

Recent Articles By Author


文章来源: https://securityboulevard.com/2026/03/hacker-uses-claude-chatgpt-ai-chatbots-to-breach-mexican-government-systems/
如有侵权请联系:admin#unsafe.sh