Mexican government breached by solo user with Claude, 150 GB exfiltrated
A solo attacker using Claude breached Mexican government systems and exfiltrated 150 GB of data. Here's why your AI security assumptions are already outdated.

Why it matters
High-profile breach using an LLM as the primary attack vector raises urgent questions about AI-assisted cybersecurity threats, government vulnerability to AI-powered social engineering, and the need for new defensive postures in the AI economy.
The key facts
12 to know150 GB of data exfiltrated from Mexican government
Attack conducted by single user leveraging Claude
Demonstrates AI model capability in social engineering/privilege escalation workflows
Published May 18, 2026
Low engagement on HN (14 points, 3 comments) suggests limited corroboration or awareness at time of analysis
UNVERIFIED
Mexican government breach attributed to solo user with Claude access
150 GB of data exfiltrated
Published May 18, 2026 on personal blog with limited corroboration
Low engagement: 14 points, 3 comments on Hacker News
Single-source claim with no official government or Anthropic statement cited
URL points to personal blog rather than established security research outlet
Go to the source
Hacker Newskonstantintkachuk.com
Publisher excerpt: Article URL: Comments URL: Points: 14 # Comments: 3