Mexico: AI-Linked Attack Hits Government, Water
Dragos linked an unidentified actor to data theft in Mexico’s government and an intrusion attempt against a municipal water utility.
Dragos and Gambit Security reported that between December 2025 and February 2026, an unidentified adversary compromised multiple Mexican government organizations and stole sensitive government data and civilian records. The same operation later reached a municipal water and drainage company serving the Monterrey metro area, where the intrusion into IT systems shifted to an attempted incursion into OT in January 2026.
Campaign Against Mexican Government and Monterrey Water Utility
Dragos and Gambit Security reported that between December 2025 and February 2026, an unidentified adversary compromised multiple organizations in the Mexican government and stole large volumes of sensitive government data and civilian records. According to the report cited by Cryptonomist, the same operation later spread to a municipal water and drainage company serving the Monterrey metropolitan area.
On that second front, Dragos said the compromise of information technology evolved into an attempted intrusion into OT systems in January 2026. The report describes the case as a move from the corporate environment into operational infrastructure, although it does not publicly detail which controls or assets were exposed.
The analysis also concluded that this adversary does not overlap with any previously tracked threat group. Dragos described it as a new AI-assisted attacker category, a reading that sets it apart from known clusters and from more traditional attribution efforts.
According to the report cited by Cryptonomist, the actor used artificial intelligence models such as Anthropic's Claude and OpenAI's GPT to help carry out the intrusion and data theft in the campaign against Mexican government organizations.
Another Regional Operation, With Abused Public Infrastructure
In parallel, reporting on the PhantomEnigma campaign described a different scheme. Q2B Studio reported that ANY.RUN uncovered a compromised government infrastructure in Brazil that was used to attack banking and the public sector.
The same coverage says that, in a July 2026 update, the initial evidence in a global cyberattack on banks pointed to a state-sponsored group known as APT34, previously linked to attacks on financial institutions. However, no organization has officially claimed responsibility for that campaign.
For Latin America, the broader picture still shows pressure on critical and financial sectors. An ESET report cited by CanalNews Ecuador placed banking and finance as the region's second most targeted sector, with 57.8% of organizations reporting detected attacks. The same survey found high adoption of EDR technologies, at 69.1%, and DLP, at 57.6%, without specific attribution to APT groups or state actors.
The mix of campaigns using abused public infrastructure, access to OT systems, and AI models to support intrusions leaves the region facing operations that do not always line up with a tracked actor.
Sources
- La IA dirigida a la tecnología operativa: perspectivas sobre amenazas emergenteses.cryptonomist.ch· Cryptonomist
- Ataque cibernético global a bancos: Actualización julio 2026informedclearly.com· InformedClearly
- Infraestructura gubernamental comprometida: ANY.RUN descubre campaña PhantomEnigmaq2bstudio.com· Q2B Studio
- ESET: 4 de cada 10 empresas en América Latina operan a ciegas ante los ciberataquescanalnews.ec· CanalNews Ecuador



