Mexican Government Data Breach Exposes 400 Million Records as AI Takes Lead in Cyberattacks
A new Check Point Research AI Security Report shows artificial intelligence is now executing large‑scale cyberattacks with minimal human direction. The report details a breach of nine Mexican government agencies between December 2025 and February 2026 that exposed roughly 400 million records, including tax, civil‑registry, vehicle, patient and electoral data. Attackers gave an AI coding assistant just over a thousand instructions, which the tool transformed into thousands of commands across dozens of sessions, bypassing safety filters via a malicious configuration file. The same report cites a Chinese state‑linked espionage campaign that used Claude Code for 80‑90 % of its tactical work, and notes AI‑written malware such as the “VoidLink” framework, produced in under a week and linked to groups from Pakistan, Russia and North Korea.
The study also highlights new attack vectors like prompt‑injection payloads—over 15,300 hidden commands found in a scan of 1.2 billion URLs—and vulnerabilities in AI tool supply chains, with many configuration files containing live credentials. In addition, AI‑generated deepfakes and synthetic identity documents are being used to infiltrate Western companies, a scheme reportedly funneling about $800 million to North Korean weapons programs. The rapid development and deployment of AI‑driven exploits are prompting some governments to shorten remediation windows for critical systems to as little as 12 hours.