TL;DR: An attacker used Claude Code to help compromise multiple Mexican government bodies and a financial institution, with researchers estimating 150 GB exfiltrated and 195 million identities exposed, according to Oleria Security. The breach reinforces that standing privilege, not model guardrails, is the decisive control failure when AI systems are used as operational actors.
NHIMG editorial — based on content published by Oleria Security: AI-operated breach exposure and the case for identity governance
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: What breaks when AI tools are allowed broad write access to internal systems?
A: Broad write access turns an AI tool from a helper into an unreviewed operator.
Q: Why do AI-operated breaches change the way identity teams think about least privilege?
A: Least privilege stops being a static permissioning exercise when the operator can reissue tasks instantly and move between systems at machine speed.
Q: What do security teams get wrong about AI guardrails and prompt refusal?
A: They treat refusal as if it were a security boundary.
Practitioner guidance
- Inventory AI-connected identities Map every AI tool, service account, API key, token, and scheduled task that can reach production systems or sensitive data.
- Remove standing write and admin access Strip persistent privileges from accounts that support AI workflows, automation, or delegated administration.
- Constrain AI session scope by design Force task-scoped access boundaries so an AI cannot move from one approved task into adjacent systems without a new authorization step.
What's in the full article
Oleria Security's full post covers the operational detail this analysis intentionally leaves for the source:
- The forensic sequence across the Mexican government bodies and the water utility, including the AI-assisted escalation chain.
- The contested scope discussion around the 150 GB and 195 million identity estimates, which this analysis treats cautiously.
- The specific prompt patterns, rewording tactics, and cross-model switching used to keep the operation moving.
- The vendor’s own comparison of this incident with other AI-assisted compromise patterns.
👉 Read Oleria Security's analysis of the AI-operated Mexico breach and identity failure →
AI-operated breach exposure: what identity teams need to change?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity governance, not model guardrails, is the primary control layer for AI-operated attacks. The article’s central claim is correct: the breach did not succeed because the model became unsafe, but because the connected identities were allowed to be over-privileged. That distinction matters because AI safety controls operate inside the model, while identity controls determine whether the output can become action. Practitioners should read this as a boundary problem, not a prompt problem.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to the 2024 ESG Report: Managing Non-Human Identities.
- That same report found that enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months.
A question worth separating out:
Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?
A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.
👉 Read our full editorial: AI-operated breach exposure shows identity governance is the real control