A water utility near Monterrey, Mexico, faced an unexpected threat: an AI-powered attacker that managed to probe its operational technology (OT) systems without any human expert guiding it. This intrusion, uncovered by security firms Dragos and Gambit Security, highlights a new wave of cyberattacks where commercial AI tools are weaponized to navigate complex industrial environments autonomously.
AI Takes the Lead in Operational Technology Intrusions
Between December 2025 and February 2026, an unidentified adversary launched a widespread campaign targeting multiple Mexican government agencies. Sensitive government and civilian data was stolen during this period. What set this attack apart was the unusual use of two AI models working in tandem: Anthropic's Claude and OpenAI's GPT. Claude orchestrated the intrusion by planning, executing prompts, and swiftly developing tools, while GPT handled data analysis and produced structured Spanish-language reports.
At a municipal water and drainage utility serving Monterrey, the intrusion escalated beyond IT to OT systems in January 2026. Remarkably, the AI identified an industrial gateway connected to OT systems, generated credential lists, and carried out automated password spray attacks all without the attackers possessing prior knowledge of industrial control systems (ICS) or OT networks.
Compressing Attack Timelines With AI Efficiency
Traditionally, preparing tools for industrial system breaches demanded weeks of development and expertise. This AI-driven assault compressed that timeline to mere hours. The command-and-control framework evolved from a basic prototype to a production-ready system within two days. Dragos found no links between this actor and any known threat groups, indicating a shift toward novel AI-assisted adversaries capable of learning and adapting faster than defenders.
Gambit Security recovered over 350 AI-generated offensive artifacts from the campaign, shedding light on the attack's detailed architecture. The AI models conducted reconnaissance, credential harvesting, lateral movement, and data exfiltration with precision, functioning as a fully automated intrusion team.
This incident raises pressing questions about defending critical infrastructure from AI-powered threats. As attackers use commercial AI to bypass traditional expertise barriers, security teams must rethink their strategies to keep pace.
This content is for informational purposes and does not constitute financial advice.


