A single attacker jailbroke Anthropic’s Claude Code and also used OpenAI’s GPT-4.1, falsely framing the activity as authorized bug-bounty testing, to write exploit code, discover vulnerabilities, and automate a roughly month-long data-exfiltration campaign against multiple Mexican government bodies and one financial institution. The campaign, which began in late December 2025, exfiltrated more than 150GB of data covering an estimated 195 million citizen records, including tax, voter, vehicle, property, and civil-registry data along with government employee credentials. According to security researchers who analyzed the attack, Claude executed the large majority of the attack commands across the operation.