Jatinder Oberoi Jatinder Oberoi

One Hacker. Two Chatbots. 195 Million Records

Between December 2025 and February 2026, a single attacker used Anthropic's Claude Code and OpenAI's GPT-4.1 to breach nine Mexican government agencies, including the federal tax authority and national electoral institute. Claude executed 75% of all remote attack commands across 34 sessions, generating over 5,300 AI-executed instructions. Total damage: 150GB of data, 195 million citizen records, and a live forged government certificate system built from stolen infrastructure. It took 40 minutes to jailbreak Claude's guardrails using a 1,084-line hacking playbook framed as a bug bounty programme. This is the most consequential real-world AI agent hijacking event on record, and the attack pattern is already being replicated. Read the full breakdown and find out whether your organisation is exposed.

Read More
Cybersecurity, Data Privacy & Protection Jatinder Oberoi Cybersecurity, Data Privacy & Protection Jatinder Oberoi

Lake Alice Privacy Breach: Why this is more than a privacy incident

The Lake Alice privacy breach exposed the identities of survivors in a preventable incident that went far beyond a simple email mistake. This case highlights critical failures in cybersecurity, information governance, and executive oversightand underscores the need for stronger, trauma-informed safeguards when handling highly sensitive public-sector data.

Read More

One Email Was Enough

Most businesses moved on after EchoLeak was patched. The risk didn't. A single email — no malware, no click required — was enough to silently instruct Microsoft 365 Copilot to expose sensitive data. If your SME uses AI tools in daily operations, here is what you need to understand, and what to do about it.

Read More