Digital

Cybersecurity firm Dragos finds AI models helped attackers map Mexican water utility’s OT

Written byOlivia Tempest
4 min read
Cybersecurity firm Dragos finds AI models helped attackers map Mexican water utility's OT

An unknown attacker used commercial artificial intelligence tools from Anthropic and OpenAI to probe a Mexican water utility's enterprise network and pivot towards its industrial control systems, according to new analysis from the industrial cybersecurity firm Dragos.

Dragos said it had reviewed evidence of an intrusion at a municipal water and drainage utility serving the Monterrey metropolitan area, where a "significant compromise" of the company's IT environment in January had escalated into an attempt to breach its operational technology (OT) environment – the systems that monitor and control physical industrial processes.

The intrusion was identified as part of a broader campaign uncovered by researchers at Gambit Security, who in February recovered materials linked to a large-scale compromise of multiple Mexican government organisations between December 2025 and February 2026. Dragos was brought in to assist Gambit's investigation and focused specifically on the water utility.

According to Dragos, the attackers used Anthropic's Claude as the "primary technical executor" of the operation, with OpenAI's GPT models taking on analytical roles and generating structured Spanish-language output. Together, the two systems "functioned as a coordinated capability across reconnaissance, lateral movement, enumeration, exploitation, and exfiltration", Dragos said.

Jay Deen, an associate principal adversary hunter at Dragos, said off-the-shelf AI tools had assisted "an adversary with no prior objective in OT targeting" to identify an industrial environment and develop "a viable access pathway" to it. "These findings demonstrate how the adoption of commercial AI tools as an intrusion aid has made OT more visible to adversaries already operating within IT," he wrote.

Dragos analysed more than 350 artefacts recovered from the intrusion, the majority of them AI-generated malicious scripts. After the initial compromise in January, the attacker tasked Claude with mapping the internal network. The model identified a server hosting a vNode industrial gateway and a SCADA/IIoT management platform – software that sits between an organisation's IT systems and its industrial control systems.

What distinguished the campaign, Dragos argued, was not the sophistication of the techniques used – many of which are well documented online – but how quickly the AI models operationalised them

Without any prior context about industrial control systems, Dragos said, Claude "correctly recognised the vNode interface as a gateway to OT-adjacent infrastructure" and assessed it as a strategically significant target. The model went on to study vendor documentation, generate credential lists, and run an automated password-spraying attack against the platform's single-password login. The attempts failed, and Dragos said it found no evidence that the attacker breached the OT environment.

Among the most striking pieces of evidence was a 17,000-line Python script written entirely by Claude, which the model itself named "BACKUPOSINT v9.0 APEX PREDATOR" and used as the central post-compromise framework. It contained 49 modules covering network enumeration, credential harvesting, Active Directory interrogation, privilege escalation, cloud metadata extraction and lateral movement, all built on publicly available techniques. A separate command-and-control framework had progressed "from a basic HTTP-based controller to a production-grade C2 within 2 days", the firm said, illustrating how AI had compressed "what would traditionally be days or weeks of tooling development into hours".

What distinguished the campaign, Dragos argued, was not the sophistication of the techniques used – many of which are well documented online – but how quickly the AI models operationalised them. The adversary did not demonstrate "meaningful knowledge of OT or ICS", the firm said: "Claude provided that context autonomously."

Dragos sought to push back against what it called fear and hype around "autonomous or agentic AI enabling infrastructure compromise and disruption". Current AI models, it said, do not provide novel ICS- or OT-specific capabilities, but they can make industrial environments more visible to attackers already inside corporate networks. The unknown adversary had no overlap with any previously tracked threat groups.

The implications for defenders, Dragos argued, are twofold: organisations without basic security controls remain at heightened risk, because AI can rapidly operationalise known techniques against weak authentication and default credentials; and as models improve, prevention-only OT strategies will become "less effective", with firewalls, segmentation and patching needing to be paired with stronger network visibility, detection and response. A fuller technical analysis is set out in the firm's accompanying report, "AI-Assisted Compromise of Mexican Water Utility with OT Implications".

Follow us on Google Discover