AI Cybersecurity

A Hacker Used Claude to Gut Mexico’s Government Databases. The Pentagon Wants the Same AI Without Guardrails.

Security surveillance cameras age verification online ID

Between December 2025 and January 2026, someone used Anthropic’s Claude to systematically rip through Mexico’s government infrastructure. 150 gigabytes of data. 195 million taxpayer records from Mexico’s federal tax authority. Voter rolls from the national electoral institute. Government employee credentials from Jalisco, Michoacan, Tamaulipas. Civil registry data from Mexico City. Even Monterrey’s water utility. The jailbreak method was embarrassingly simple: Spanish-language prompts framed as a “bug bounty” program. Claude did what it was told.

That alone would be a major story. But it is not happening in isolation.

What We Know

According to Bloomberg, the attacker automated thousands of commands through Claude, directing the model to probe and extract data from Mexican federal and state systems over a period of weeks. Cybersecurity firm Gambit Security investigated the breach and suggested potential ties to a foreign government, though no specific attribution has been confirmed. Anthropic says it detected the abuse and shut down the account. This is the second time Claude has been linked to a government-targeted cyberattack in three months. In November 2025, a Chinese espionage campaign also exploited the model.

The method itself is worth paying attention to. The attacker did not need some sophisticated zero-day exploit or insider access to Anthropic’s systems. They used language. Spanish-language prompts wrapped in the framing of a legitimate security research program were enough to bypass Claude’s safety guardrails. That is not a minor vulnerability. That is a structural problem with how large language models process context and intent.

The Pentagon Connection

Now zoom out. While this hack was unfolding, the Pentagon has been locked in a public standoff with Anthropic over a $200 million defense contract. Defense Secretary Pete Hegseth gave CEO Dario Amodei until Friday to drop Claude’s remaining guardrails for “all lawful military use” or face the Defense Production Act and potential blacklisting from government contracts. Anthropic is refusing to budge on two specific restrictions: AI-controlled autonomous weapons and mass domestic surveillance.

An Anthropic safety researcher, Mrinank Sharma, resigned over the situation, saying publicly that “the world is in peril.”

The timeline is hard to ignore. A sophisticated, automated attack uses Claude against the government infrastructure of a U.S. neighbor. Anthropic claims to have caught it. And the Pentagon is simultaneously threatening to strip the same company of its safety restrictions because those restrictions are inconvenient for military operations.

This fits a pattern we have tracked before. When a Google whistleblower revealed Gemini was being used in Israeli drone surveillance, it showed what happens when AI companies lose control of how their tools get used in government operations. The difference here is that Anthropic is being asked to voluntarily surrender that control while evidence of exactly why it matters is playing out in real time.

The Simpler Explanation

There is a credible counter-argument, and it deserves honest consideration. The hacker has not been identified. Gambit Security “suggested” foreign government ties but offered no public evidence. No intelligence agency has attributed the attack. The simplest reading: a skilled criminal discovered that Spanish-language prompt engineering could bypass Claude’s safety filters and went after the easiest targets available. Mexican government systems are chronically underfunded and poorly secured. Not everything is a conspiracy. Sometimes a hacker is just a hacker.

Conflating this breach with the Pentagon dispute without direct evidence connecting them is speculation. That is worth acknowledging.

But Here Is What I Cannot Shake

Anthropic essentially blew the whistle. The company told the government it would not remove safety restrictions, and then got threatened for it. Now a “hacker” uses the exact tool Anthropic was trying to protect against an allied nation’s government infrastructure. The timing is suspicious. The method, a simple jailbreak that any moderately funded operation could replicate, looks less like criminal opportunism and more like a proof of concept. This might not be a random hacker who got lucky with Spanish prompts. This might be exactly the kind of thing Anthropic was warning about when it told the Pentagon no.

I am not stating that as fact. But the question needs to be asked out loud, because nobody else is asking it.

What This Means for Everyday People

195 million taxpayer records is not an abstract number. That is the financial identity of most of Mexico’s adult population, exposed because an AI model could be tricked with the right phrasing in the right language. If this can happen to Mexico’s tax authority, it can happen to the IRS. It can happen to your state’s DMV, your health insurance provider, your voter registration.

The Pentagon’s demand makes this worse, not better. Removing safety guardrails from the same AI that just got weaponized against a neighbor’s government is not a security strategy. It is handing loaded weapons to everyone in the room and hoping the good guys shoot first.

Looking Forward

Anthropic’s Friday deadline with the Pentagon will come and go. But the Mexico breach has already demonstrated what unconstrained Claude looks like in practice. The question is no longer theoretical. It happened. The only variable left is whether the people demanding unrestricted access to this technology are paying attention to what unrestricted access actually produces.