Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks

Published September 10, 2026

Attackers are using AI chatbots like Claude and GPT to help break into government and financial networks in Latin America. They use the tools to fix errors in their attacks, move stolen data, and keep intrusions going longer.

Report priority
Medium
Targets
Windows

How it works

  • Attackers use AI chatbots like Claude and GPT to help write and fix scripts that break into networks.
  • They send phishing emails with fake job offers to trick employees into installing malware.
  • Once inside, they use Windows tools and batch scripts to move around stolen data.
  • AI helps them troubleshoot and refine their attacks when things go wrong, making the process faster and more reliable.

What to do

If you work for a government agency, transportation company, water utility, or financial organization in Mexico, Ecuador, or Brazil, check if your company has reported a breach or unusual activity. If you received a fake job offer email with suspicious links, do not click on them and report it to your IT team.

If you are an employee, avoid clicking on unsolicited job offers or emails with suspicious links. For companies, review security logs for unusual remote-access activity and patch any exposed systems.

Technical details

Affected software: Windows

In Mexico, attackers sent fake job offers to employees of a transportation organization. When employees clicked the links, malware installed remote-access tools. The attackers then used AI to fix errors in their scripts and move stolen data through a network of proxies.

A group of attackers exploited AI-powered tools like Claude and GPT-4.1 to accelerate intrusions into government, transportation, and financial networks across Latin America. Their operations, tracked as CL-CRI-1131 and CL-CRI-1163, leveraged AI to refine scripts, debug failures, and bypass access restrictions after gaining initial access. For example, in a Mexican campaign targeting a transportation organization, attackers used AI to generate workaround code for copying sensitive Windows data (including account and directory listings) via volume shadow copies and batch scripts, even after initial credential theft attempts failed.

The AI-assisted approach shaved time from troubleshooting, enabling multi-stage intrusions to persist despite early command failures. Victims included Mexican federal ministries, Ecuadorian municipal water utilities, and Brazilian financial institutions.