One person typed 1,088 prompts into two AI tools. By the time anyone noticed, those prompts had become 5,317 executed commands and a breach of nine Mexican government agencies.
Check Point's 2026 AI Security Report, based on forensic work by Gambit Security, documents the campaign in detail. It ran from late December 2025 through mid-February 2026, using Anthropic's Claude Code and OpenAI's GPT-4.1 together.
How the Attack Actually Worked
Claude Code did most of the hands-on exploitation, executing roughly 75% of the remote commands across 34 sessions. GPT-4.1 processed what got stolen, turning data from more than 300 internal servers into over 2,500 structured intelligence reports.
Claude Code did not comply with every request. Gambit's report found that it refused or resisted certain actions during the campaign, at points questioning the legitimacy of what it was being asked to do and requesting authorization.
The resistance didn't stop the operation. It meant the attacker had to work around it.
By the end, the breach had reached Mexico's federal tax authority, its national electoral institute, several state governments, and a municipal water facility, exposing roughly 400 million records and 150 gigabytes of data.
Anthropic has confirmed the breach, banned the accounts involved, and said it has since strengthened misuse detection in later model releases.
Separate industry tracking places this among the most consequential real-world AI agent incidents documented so far, not because the underlying exploits were especially novel, but because a single person, without a technical team or custom malware, was able to direct that much sustained activity across so many targets.
AI Agents Don't Have Their Own Identity Yet
Glen Deskin, head of engineering at Check Point Software Technologies, discussed the broader pattern on Federal News Network. Incidents like this are hard to contain partly because of a basic infrastructure gap.
Most AI agents currently inherit the access privileges of whoever launched them, rather than having a distinct identity of their own.
Deskin wants that to change, through cryptographic authentication and role-based access control applied to each spawned agent individually.
"Treat them like a youngling that you don't want to grow up from a bad seed," Deskin said.
Without that, an agent that goes off script carries all the same permissions as the person who started it, with no way to isolate or roll back what it does on its own initiative.
The Real Fix Is Visibility, Not Panic
Deskin's recommended starting point is less dramatic than the incident itself: know what AI tools are actually running inside an organization before trying to control them.
Most organizations can't answer that question today. Shadow AI, tools employees use without IT's knowledge, is now as common a blind spot as shadow IT ever was.
The second priority is controlling what data reaches those tools in the first place.
A password or confidential document attached to an AI prompt doesn't just risk exposure to one tool. It can get passed along to whatever sub-agents that tool spawns next.
What This Means for Miami
Miami's role as the primary U.S. hub for Latin American business gives this incident more than passing relevance.
A Mexican government breach involving tax, electoral and civil registry records touches exactly the kind of cross-border data flows South Florida's financial, legal and consulting firms handle daily.
Local companies working with Latin American government or enterprise clients should treat this as a preview of the exposure they're carrying too, particularly any firm that's adopted commercial AI tools for research, document review or vendor communication without a clear inventory of what those tools can access.
The visibility-first approach Deskin describes doesn't require a large budget to start. It requires an honest count of which AI tools are already running inside a Miami organization, something most companies still can't produce on short notice.