Skip to content
AI SecurityCritical InfrastructureICSOT Security

Claude guided hackers to a water utility's OT systems. This is what happened.

2 min read
Share

The campaign

Between December 2025 and February 2026, an unidentified threat actor ran a campaign against multiple Mexican government organizations. One target was a municipal water and drainage utility in Monterrey. Gambit Security uncovered the campaign and brought in Dragos specifically to evaluate the risk to industrial control systems at the water utility. Dragos's report, released in September 2026, provides the most detailed public account to date of AI being used offensively to target water sector OT.

Claude's role in the attack

What distinguished this intrusion was the division of AI labor. The attacker used Claude as the primary technical workhorse: intrusion planning, tool development, and problem-solving. GPT handled victim data processing. Together, the two models served as an AI-assisted operational engine. Claude actively guided the attacker toward OT and SCADA assets within the utility's environment. This is not a case of AI replacing a skilled attacker; it is a case of AI lowering the skill floor for targeting OT-specific systems that would otherwise require specialized knowledge.

Why water sector OT matters

Water and wastewater systems are among the most exposed critical infrastructure sectors: they are typically under-resourced, rely on legacy OT systems with long replacement cycles, and are essential to public health. A successful attack on a water treatment or distribution system has direct, visible consequences for a city's population. The Monterrey case does not appear to have caused operational impact, but the pattern of targeting is the warning.

What OT defenders should take from this

  • Assume AI-assisted attacker reconnaissance: adversaries no longer need deep OT expertise to identify control system assets and paths toward them. Your OT network segmentation and asset visibility need to be current and verified.
  • IT-to-OT jump paths are the primary risk surface: the Monterrey attack navigated from IT into OT. Enforce strict IT/OT segmentation and monitor crossing points for anomalous traffic.
  • Dragos's report includes IOCs and tactics from the Monterrey campaign. If you run water sector OT, review the full advisory and compare these indicators against your telemetry.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you work in OT or critical infrastructure security and want to discuss this incident.