AI targeting operational technology probed a water utility - no expertise needed

A water utility serving a major metropolitan area came within reach of an adversary it never saw coming — one that didn’t need specialized industrial knowledge because it had something more powerful: commercial AI that could figure it out on the fly. The case, investigated by Dragos and Gambit Security, marks one of the first documented real-world instances of AI targeting operational technology infrastructure during an active intrusion, and it raises a question the security industry hasn’t fully answered yet: how do you defend against an attacker who can learn your environment faster than you can map it?
Key takeaways
- An unknown adversary used Anthropic’s Claude and OpenAI’s GPT to conduct a large-scale intrusion against multiple Mexican government organizations between December 2025 and February 2026.
- Dragos and Gambit Security investigated a related breach of a municipal water and drainage utility serving the Monterrey metropolitan area, where the IT compromise escalated into an attempted OT breach in January 2026.
- Claude autonomously identified an OT-adjacent industrial gateway, generated credential lists, and launched an automated password spray attack — all without the adversary having prior ICS or OT knowledge.
- AI compressed what would traditionally take days or weeks of tooling development into hours, with a command-and-control framework going from basic to production-grade within two days.
- Dragos found no overlap between this adversary and any previously tracked threat group, underlining the emergence of a new category of AI-assisted attacker.
AI-Powered Intrusion Campaign Targeting Mexican Government and Water Utility
The campaign’s scale was striking. Between December 2025 and February 2026, an unidentified adversary compromised multiple Mexican government organizations, stealing large volumes of sensitive government data and civilian records. Researchers at Gambit Security recovered over 350 artifacts — predominantly AI-generated offensive scripts — that revealed the intrusion’s architecture in unusual detail.
… Continue reading the full article at the original source below.
