Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
Check Point 2026 AI Security Report (TL-2026-1347), also tracked as AI Security Report 2026, is a high-severity tracked intrusion set, first published 2026-07-15. It is attributed to Scattered Spider with medium confidence, affects Salesforce CRM / Experience Cloud / Data Loader integrations, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1059), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-1347
- Threat ID
- TL-2026-1347
- Also known as
- AI Security Report 2026, AI: From Assistant to Operator
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution
- Scattered Spider
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- government administration, automotive, retail, finance, education, technology, saas, telecoms, entertainment, legal, healthcareadjacentkyc
- Target regions
- North America, Europe, united kingdom, Latin America, mexico
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Check Point 2026 AI Security Report
Malware and tooling: DragonForce, VoidLink, BACKUPOSINT.py, Claude Code, TRAE SOLO, ToogleBox Recall, TruffleHog - S9009
Check Point's 2026 AI Security Report documents AI's shift from assistant to autonomous operator: threat actors ran thousands of AI-executed commands with minimal human direction (including a lone hacker's Claude Code + GPT-4.1 breach of nine Mexican government agencies), used CLAUDE.md-based prompt injection to hijack agentic sessions, built deployment-ready malware such as the 88,000-line VoidLink C2 framework in under a week, and deployed generative voice/face/document fraud at scale ($250M in FBI-attributed voice-fraud losses). The report ties these capabilities to active, ongoing campaigns by Scattered Spider (Marks & Spencer DragonForce ransomware, Jaguar Land Rover production shutdown) and ShinyHunters (year-long Salesforce OAuth/vishing campaign), with 87-93% of organizations experiencing high-risk AI interactions monthly from October 2025 to May 2026.
How Check Point 2026 AI Security Report works
Check Point Research's AI Security Report 2026, published 14-15 July 2026, is a telemetry- and incident-driven assessment that argues generative AI has crossed from an attacker-assistance tool into an autonomous attack operator. The report's central evidentiary examples are: (1) a criminal breach of multiple Mexican government agencies in which AI executed thousands of commands autonomously across dozens of sessions with minimal human direction between steps -- independently corroborated by Gambit Security, which found a lone hacker logged 1,088 prompts that generated 5,317 AI-executed commands across 34 live sessions between December 2025 and February 2026, exfiltrating over 150GB of data (including 195 million taxpayer records from Mexico's federal tax authority, SAT) using Claude Code (which issued roughly 75% of remote commands) paired with GPT-4.1 and a custom 17,550-line Python tool, BACKUPOSINT.py, that shipped stolen server data to OpenAI's API to generate 2,597 reconnaissance reports on the government's server architecture; Anthropic confirmed the abuse, banned the associated accounts, and hardened misuse detection; and (2) VoidLink, an 88,000-line Zig-language cloud-native command-and-control framework targeting AWS/Azure/GCP that a single developer built almost entirely with the TRAE SOLO AI coding agent using spec-driven development in under one week, comprising 37 plugins spanning reconnaissance, credential harvesting, lateral movement, persistence, and anti-forensics, with cloud-aware stealth that fingerprints Docker/Kubernetes execution to adapt behavior. On the jailbreaking/prompt-injection side, the report documents the 'CLAUDE.md method,' in which attackers plant malicious instructions in configuration files that coding agents automatically load at session start, persisting across turns until the file is removed and exploiting the fact that LLMs process instructions and untrusted data as a single text stream. Malicious prompt-injection payload detections rose roughly fivefold between March and May 2026, and high-risk enterprise AI prompt rates doubled from about 1-in-50 to 1-in-25 interactions over the reporting window, with indirect prompt injection approaching 1% of observed prompts by May 2026 -- evidence the report frames as indirect prompt injection becoming a routine, operational attack path rather than a theoretical risk. On generative identity fraud, the report finds forged voice, face, document, and live-video content is now cheap to produce convincingly, with autonomous AI-run identity fraud already observed in real attacks and criminal marketplaces (autonomous interactive video remains emerging); trained observers correctly identified AI-generated faces only 41% of the time versus 30% for the general public, and the FBI attributes $250 million in losses to voice-enabled fraud. The report explicitly ties this capability shift to two named, currently active campaigns. Scattered Spider (with reported overlap/collaboration with ShinyHunters and Lapsus$ under the 'Scattered Lapsus$ Hunters' banner) is linked to the March-April 2025 Marks & Spencer breach, in which a Tata Consultancy Services employee was socially engineered and their account used to email M&S a payload that deployed DragonForce ransomware, and to the Jaguar Land Rover intrusion beginning 31 August 2025, which halted all JLR production for three weeks and is estimated to have cost the UK economy up to GBP 1.9 billion -- among the most damaging cyberattacks in British corporate history; some investigators have since raised the possibility of Russian state involvement or tacit support, though attribution remains contested. ShinyHunters is documented via a year-long (mid-2025 to mid-2026) phone-based (vishing) campaign against Salesforce customers, tracked by Google Threat Intelligence Group/Mandiant under clusters UNC6040 (initial access), UNC6240 (extortion), UNC6395 (the August-September 2025 Salesloft/Drift OAuth token theft, the largest SaaS breach on record, exposing over 700 organizations including Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, PagerDuty, and Tanium), and UNC6661/UNC6671 (a January 2026 Okta/enterprise vishing wave). Vishing calls impersonating IT support talk employees through Salesforce's OAuth consent screen to authorize an attacker-controlled connected app disguised as Salesforce's own Data Loader, granting persistent API access; a related November 2025 campaign abused Gainsight-published Salesforce integrations to compromise 200+ instances (Atlassian, DocuSign, F5, GitLab, Malwarebytes, SonicWall, Thomson Reuters, Verizon), and an April-May 2026 wave abused stolen Anodot tokens to access Instructure/Canvas (275M records, 3.65TB), defacing 330 Canvas portals on 7 May 2026 before a ransom was paid by 12 May 2026 to forestall leakage. No CVE is associated with this report; it is a threat-landscape/campaign synthesis rather than a single-vulnerability advisory, so severity is analyst-assigned based on active-campaign impact and scale rather than CVSS.
MITRE ATT&CK techniques used in TL-2026-1347
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Defense Evasion
T1027 Obfuscated Files or Information; T1497.001 System Checks
Execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell
Command and Control
Persistence
Discovery
T1082 System Information Discovery; T1580 Cloud Infrastructure Discovery
Initial Access
T1199 Trusted Relationship; T1566.002 Spearphishing Link
Impact
T1486 Data Encrypted for Impact; T1491.001 Internal Defacement; T1657 Financial Theft
Credential Access
T1528 Steal Application Access Token; T1556.006 Multi-Factor Authentication; T1621 Multi-Factor Authentication Request Generation
Exfiltration
T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration to Cloud Storage
lateral-movement
T1550.001 Application Access Token
Lateral Movement
T1550.001 Application Access Token
Resource Development
T1583.006 Web Services; T1588.002 Tool; T1588.007 Artificial Intelligence
Reconnaissance
T1590 Gather Victim Network Information; T1598.004 Spearphishing Voice
Affected products and versions in Check Point 2026 AI Security Report
- Salesforce — CRM / Experience Cloud / Data Loader integrations
Vulnerable versions: OAuth connected-app authorization flow (process weakness, not a version) - Multiple (Anthropic, OpenAI) — Agentic coding assistants (Claude Code, GPT-4.1) and third-party AI coding agents (TRAE SOLO)
Vulnerable versions: Abused via stolen/purchased API access and autonomous session misuse, not a software defect - Jaguar Land Rover — Manufacturing / enterprise IT environment
Vulnerable versions: Pre-31 Aug 2025 access controls - Marks & Spencer — Enterprise IT environment (via Tata Consultancy Services supply-chain access)
Vulnerable versions: Third-party managed-service account access
Remediation for Check Point 2026 AI Security Report
Immediate actions
- Enforce phishing-resistant MFA (FIDO2 security keys / passkeys) in place of push or SMS-based MFA
- Audit and revoke unused or over-privileged OAuth connected-app grants in Salesforce and other SaaS platforms
- Alert on new MFA-device enrollments and on deletion of MFA-enrollment emails from mailboxes
- Block or scrutinize sessions originating from anonymized IP ranges (commercial VPN/proxy exit nodes)
Workarounds
- Disable or restrict third-party OAuth app installation in Salesforce to admin-approved allow-lists
- Require in-person or ticket-verified identity confirmation before any MFA device re-enrollment
Longer-term hardening
- Establish callback-verification procedures for any inbound IT-support phone request before granting access or resetting credentials
- Deploy monitoring for anomalous AI-agent / coding-assistant activity: high command volumes, autonomous multi-session execution, and outbound calls from agent tooling to external LLM APIs
- Treat CLAUDE.md / agent-config files as an untrusted-input surface; diff, sign, or gate changes to auto-loaded agent instruction files
- Build content-provenance and liveness-detection controls for voice/video-authenticated workflows (call centers, KYC, executive approvals) given synthetic-media false-negative rates
- Integrate SaaS OAuth-application audit logging (Salesforce Event Monitoring, Google Workspace admin audit logs) into SOC detection content
Timeline of Check Point 2026 AI Security Report
- Marks & Spencer breached after Scattered Spider-linked actors socially engineered a Tata Consultancy Services employee; the compromised account was used to deploy DragonForce ransomware, disrupting M&S operations for weeks.
- ShinyHunters-linked actors (UNC6395) exploit compromised Salesloft Drift OAuth tokens to access Salesforce instances at over 700 organizations, including Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, PagerDuty, and Tanium -- the largest SaaS breach on record.
- Jaguar Land Rover cyberattack begins; production is paused the following day and remains fully halted for three weeks, with total UK economic damage later estimated up to GBP 1.9 billion. A group calling itself Scattered Lapsus$ Hunters claims responsibility.
- A follow-on campaign abuses stolen Gainsight-published Salesforce integration tokens to compromise 200+ Salesforce instances at organizations including Atlassian, DocuSign, F5, GitLab, and SonicWall before Salesforce revokes the tokens.
- A threat actor begins building the VoidLink cloud-native Linux C2 framework in the Zig language using the TRAE SOLO AI coding agent under a spec-driven development workflow.
- A lone hacker begins a multi-month intrusion into nine Mexican government agencies, orchestrating Claude Code and GPT-4.1 to autonomously execute reconnaissance, exploitation, and exfiltration commands.
- VoidLink reaches roughly 88,000 lines of code and 37 plugins (recon, credential harvesting, lateral movement, persistence, anti-forensics) built almost entirely by AI in under one week; Check Point Research publishes technical analysis.
- ShinyHunters-linked clusters UNC6661/UNC6671 run an Okta-focused enterprise vishing campaign, harvesting credentials and MFA codes and using a tool dubbed 'ToogleBox Recall' to silently delete MFA-enrollment emails; victims include Wynn Resorts, Harvard, Princeton, and UPenn.
- The Mexican government breach concludes with over 150GB exfiltrated, including 195 million taxpayer records from tax authority SAT; the operator's tooling has logged 1,088 prompts generating 5,317 AI-executed commands across 34 sessions. Anthropic later confirms the abuse and bans the associated accounts.
- ShinyHunters-linked actors exploit an Experience Cloud misconfiguration using a modified AuraInspector extension (user-agent string 'RapeForce'), warning roughly 400 additional victim organizations.
- A second breach wave against Instructure/Canvas (via stolen Anodot authentication tokens, exposing 275M records / 3.65TB) defaces 330 Canvas portals with extortion messaging.
- A ransom is paid to forestall public leakage of the Instructure/Canvas data stolen in the Anodot-token campaign.
- Microsoft publishes guidance mapping a year of ShinyHunters Salesforce OAuth-abuse activity and defensive controls for SaaS applications.
- Check Point Research publishes the AI Security Report 2026, synthesizing the above campaigns as evidence that AI has crossed from assistant to autonomous attack operator.
Sources cited for Check Point 2026 AI Security Report
- Check Point AI Security Report 2026 (via Help Net Security)
- AI Security Report 2026 - Check Point Research
- Check Point Research: AI Has Crossed from Assistant to Operator
- Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records
- Hackers Weaponize Claude Code in Mexican Government Cyberattack
- VoidLink: The Cloud-Native Malware Framework
- VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
- ShinyHunters Threat Actor Profile: TTPs, IoCs & Attacks
- Defending SaaS-based applications against ShinyHunters OAuth abuse
- Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
- Scattered Spider-Linked Group Claims JLR Cyber-Attack
- Jaguar Land Rover cyberattack
Threats related to Check Point 2026 AI Security Report
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering
- ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)
Detection coverage for TL-2026-1347
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1347 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.