A water utility serving a major metropolitan area came within reach of an adversary it never saw coming — one that didn’t need specialized industrial knowledge because it had something more powerful: commercial AI that could figure it out on the fly. The case, investigated by Dragos and Gambit Security, marks one of the first documented real-world instances of AI targeting operational technology infrastructure during an active intrusion, and it raises a question the security industry hasn’t fully answered yet: how do you defend against an attacker who can learn your environment faster than you can map it?
Key takeaways
An unknown adversary used Anthropic’s Claude and OpenAI’s GPT to conduct a large-scale intrusion against multiple Mexican government organizations between December 2025 and February 2026.
Dragos and Gambit Security investigated a related breach of a municipal water and drainage utility serving the Monterrey metropolitan area, where the IT compromi
We współpracy z: https://en.cryptonomist.ch/2026/07/26/ai-targeting-operational-technology/