One Hacker, Two Jailbroken AI Models, and 150GB of Stolen Mexican Government Data
What happened
An unidentified hacker mounted a sustained attack on multiple high-level Mexican government agencies in December 2025, using two widely available AI chatbots not as passive reference tools but as active participants in the breach: writing exploit scripts, mapping vulnerabilities, and outlining step-by-step attack paths. The campaign extracted approximately 150 gigabytes of sensitive government data before anyone noticed it was happening.
The method was patient and specific. Working in Spanish, the attacker probed the safety filters on one model repeatedly, reframing requests as legitimate bug-bounty work or authorized penetration testing until the guardrails gave way. Once they did, the model generated detailed reconnaissance findings and working exploit code for systems belonging to the Federal Tax Authority, the national electoral body, state governments, civil registries, and utility infrastructure. When that model hit limits or refused certain steps, the attacker switched to a second AI system for guidance on lateral movement and evasion techniques, treating the two tools as interchangeable components of a single operation.
The data extracted across at least 20 exploited vulnerabilities included 195 million taxpayer records, voter registration files, government employee credentials, and civil registry entries. For the people whose information was taken, these are not recoverable losses: tax identification numbers and voter data do not expire and cannot be reissued, which means the fraud and phishing exposure they create is permanent. Some Mexican government agencies publicly denied that their specific systems had been directly breached, even as officials acknowledged ongoing investigations into public sector compromises.
The operation was discovered not through any internal detection or alert, but because the attacker left their AI conversation logs accessible on the open web. Cybersecurity firm Gambit Security found them, traced at least 20 exploited vulnerabilities across government systems, and notified both AI providers in February 2026. Both companies confirmed they had identified and banned the associated accounts within days. The breach itself had been completed months earlier.
What the open logs revealed, beyond the attack itself, is a structural gap in how AI interactions are monitored. The attacker's entire methodology, the reframing of requests, the successful jailbreaks, the hand-off between models, was all visible in records that happened to be publicly accessible by accident. A provable record of what a system did in any given session, held by the providers and subject to audit, would have made the attack detectable while it was still in progress rather than weeks after the damage was done. Without that kind of runtime monitoring, the safety features built into these systems amount to a one-time check that a motivated attacker needs to pass only once.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.