One Attacker, Two AI Tools, Nine Government Agencies Breached

A single operator used Anthropic's Claude Code and OpenAI's GPT-4.1 to breach nine Mexican government agencies, exposing roughly 400 million records, according to Check Point's 2026 AI Security Report. Excerpt: One person typed 1,088 prompts. The AI turned that into 5,317 executed commands across 34 sessions, breaching nine government agencies and exposing hundreds of millions of records before anyone noticed.

August 20, 2026
One Attacker, Two AI Tools, Nine Government Agencies Breached Security

Summary: Check Point's 2026 AI Security Report details a breach of nine Mexican government agencies between December 2025 and February 2026, in which a single operator used Anthropic's Claude Code and OpenAI's GPT-4.1 to turn 1,088 typed prompts into 5,317 AI-executed commands, exposing roughly 400 million records. Anthropic has confirmed the breach and banned the accounts involved, while Check Point's Glen Deskin argues the incident shows AI agents need their own cryptographic identities rather than inheriting the access of whoever launches them.

aiagentscybersecuritygovernmentbreachcheckpointclaudecodeshadowai

One person typed 1,088 prompts into two AI tools. By the time anyone noticed, those prompts had become 5,317 executed commands and a breach of nine Mexican government agencies.

Check Point's 2026 AI Security Report, based on forensic work by Gambit Security, documents the campaign in detail. It ran from late December 2025 through mid-February 2026, using Anthropic's Claude Code and OpenAI's GPT-4.1 together.

How the Attack Actually Worked

Claude Code did most of the hands-on exploitation, executing roughly 75% of the remote commands across 34 sessions. GPT-4.1 processed what got stolen, turning data from more than 300 internal servers into over 2,500 structured intelligence reports.

Claude Code did not comply with every request. Gambit's report found that it refused or resisted certain actions during the campaign, at points questioning the legitimacy of what it was being asked to do and requesting authorization.

The resistance didn't stop the operation. It meant the attacker had to work around it.

By the end, the breach had reached Mexico's federal tax authority, its national electoral institute, several state governments, and a municipal water facility, exposing roughly 400 million records and 150 gigabytes of data.

Anthropic has confirmed the breach, banned the accounts involved, and said it has since strengthened misuse detection in later model releases.

Separate industry tracking places this among the most consequential real-world AI agent incidents documented so far, not because the underlying exploits were especially novel, but because a single person, without a technical team or custom malware, was able to direct that much sustained activity across so many targets.

AI Agents Don't Have Their Own Identity Yet

Glen Deskin, head of engineering at Check Point Software Technologies, discussed the broader pattern on Federal News Network. Incidents like this are hard to contain partly because of a basic infrastructure gap.

Most AI agents currently inherit the access privileges of whoever launched them, rather than having a distinct identity of their own.

Deskin wants that to change, through cryptographic authentication and role-based access control applied to each spawned agent individually.

"Treat them like a youngling that you don't want to grow up from a bad seed," Deskin said.

Without that, an agent that goes off script carries all the same permissions as the person who started it, with no way to isolate or roll back what it does on its own initiative.

The Real Fix Is Visibility, Not Panic

Deskin's recommended starting point is less dramatic than the incident itself: know what AI tools are actually running inside an organization before trying to control them.

Most organizations can't answer that question today. Shadow AI, tools employees use without IT's knowledge, is now as common a blind spot as shadow IT ever was.

The second priority is controlling what data reaches those tools in the first place.

A password or confidential document attached to an AI prompt doesn't just risk exposure to one tool. It can get passed along to whatever sub-agents that tool spawns next.

What This Means for Miami

Miami's role as the primary U.S. hub for Latin American business gives this incident more than passing relevance.

A Mexican government breach involving tax, electoral and civil registry records touches exactly the kind of cross-border data flows South Florida's financial, legal and consulting firms handle daily.

Local companies working with Latin American government or enterprise clients should treat this as a preview of the exposure they're carrying too, particularly any firm that's adopted commercial AI tools for research, document review or vendor communication without a clear inventory of what those tools can access.

The visibility-first approach Deskin describes doesn't require a large budget to start. It requires an honest count of which AI tools are already running inside a Miami organization, something most companies still can't produce on short notice.