Mexico Govt, Monterrey Water Hit by AI Actor
An unknown AI-assisted actor hit Mexican government agencies and a Monterrey water utility. Dragos did not link it to known APTs.
An unidentified adversary used AI models including Anthropic's Claude and OpenAI's GPT in a large-scale intrusion against multiple Mexican government organizations from December 2025 through February 2026. The same analysis also ties a separate case to a municipal water and drainage company serving the Monterrey metro area, where an initial IT compromise in January 2026 led to an attempted intrusion into operational technology.
An unidentified adversary used AI models including Anthropic's Claude and OpenAI's GPT in a large-scale intrusion against multiple Mexican government organizations from December 2025 through February 2026. According to the analysis cited by Cryptonomist, the operation led to the theft of large volumes of sensitive government data and civilian records.
The Monterrey case
The same report, based on research from Dragos and Gambit Security, links that activity to a related breach involving a municipal water and drainage company serving the Monterrey metropolitan area. There, an initial compromise of information technology moved in January 2026 into an attempted breach of operational technology infrastructure, underscoring the convergence between corporate access and industrial systems.
Dragos said it found no overlap between this adversary and any previously tracked threat group. In that assessment, this was a new AI-assisted actor, with no specific attribution to a known APT or state actor.
Regional context
The incident comes as Mexico also appears in a threat landscape report on the banking and insurance sector cited by Portafolio. That analysis says Latin America recorded the world’s highest relative growth in cyberattacks against the financial sector in 2025.
Portafolio added that ransomware accounted for 79% of financial incidents in the region, and that Brazil, Mexico, Argentina, Colombia and Peru made up about half of the reported cases. The same material does not specify which of those events involved APT attacks or state actors.
Sources
- La IA dirigida a la tecnología operativa: perspectivas sobre amenazas emergenteses.cryptonomist.ch· Cryptonomist
- El nuevo gran riesgo del sistema financieroportafolio.co· Portafolio



