2026 Mexican Government — 195M records, 150GB (Claude AI–assisted)
Data compromised
Taxpayer records, voter records, government credentials, civil registry files
Technical writeup
Solo attacker used Anthropic Claude AI to breach multiple Mexican government agencies Dec 2025–Jan 2026. Jailbroken Claude generated reconnaissance scripts, SQL injection payloads, and credential-stuffing automation. ~20 vulnerabilities exploited; ~150GB exfiltrated. Affected: federal tax authority, national electoral institute, state governments (Jalisco, Michoacán, Tamaulipas), Mexico City civil registry, Monterrey water utility. Exposed: ~195M taxpayer records, voter records, government employee credentials, civil registry files.
Root cause
Claude AI jailbreaking; role-play bypass of safety guardrails; SQL injection, credential stuffing