Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns — Threadlinqs Intelligence
As of 2026-07-15, Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns is a high-severity threat intel threat attributed to Scattered Spider, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1347 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Scattered Spider · FINANCIAL
Check Point's 2026 AI Security Report documents AI's shift from assistant to autonomous operator: threat actors ran thousands of AI-executed commands with minimal human direction (including a lone
Check Point Research's AI Security Report 2026, published 14-15 July 2026, is a telemetry- and incident-driven assessment that argues generative AI has crossed from an attacker-assistance tool into an autonomous attack operator. The report's central evidentiary examples are: (1) a criminal breach of multiple Mexican government agencies in which AI executed thousands of commands autonomously across dozens of sessions with minimal human direction between steps -- independently corroborated by Gambit Security, which found a lone hacker logged 1,088 prompts that generated 5,317 AI-executed commands across 34 live sessions between December 2025 and February 2026, exfiltrating over 150GB of data (including 195 million taxpayer records from Mexico's federal tax authority, SAT) using Claude Code (which issued roughly 75% of remote commands) paired with GPT-4.1 and a custom 17,550-line Python tool, BACKUPOSINT.py, that shipped stolen server data to OpenAI's API to generate 2,597 reconnaissance reports on the government's server architecture; Anthropic confirmed the abuse, banned the associated accounts, and hardened misuse detection; and (2) VoidLink, an 88,000-line Zig-language cloud-native command-and-control framework targeting AWS/Azure/GCP that a single developer built almost entirely with the TRAE SOLO AI coding agent using spec-driven development in under one week, comprising 37 plugins spanning reconnaissance, credential harvesting, lateral movement, persistence, and anti-forensics, with cloud-aware stealth that fingerprints Docker/Kubernetes execution to adapt behavior. On the jailbreaking/prompt-injection side, the report documents the 'CLAUDE.md method,' in which attackers plant malicious instructions in configuration files that coding agents automatically load at session start, persisting across turns until the file is removed and exploiting the fact that LLMs process instructions and untrusted data as a single text stream. Malicious prompt-injection payload detections rose roughly fivefold between March and May 2026, and high-risk enterprise AI prompt rates doubled from about 1-in-50 to 1-in-25 interactions over the reporting window, with indirect prompt injection approaching 1% of observed prompts by May 2026 -- evidence the report frames as indirect prompt injection becoming a routine, operational attack path rather than a theoretical risk. On generative identity fraud, the report finds forged voice, face, document, and live-video content is now cheap to produce convincingly, with autonomous AI-run identity fraud already observed in real attacks and criminal marketplaces (autonomous interactive video remains emerging); trained observers correctly identified AI-generated faces only 41% of the time versus 30% for the general public, and the FBI attributes $250 million in losses to voice-enabled fraud. The report explicitly ties this capability shift to two named, currently active campaigns. Scattered Spider (with reported overlap/collaboration with ShinyHunters and Lapsus$ under the 'Scattered Lapsus$ Hunters' banner) is linked to the March-April 2025 Marks & Spencer breach, in which a Tata Consultancy Services employee was socially engineered and their account used to email M&S a payload that deployed DragonForce ransomware, and to the Jaguar Land Rover intrusion beginning 31 August 2025, which halted all JLR production for three weeks and is estimated to have cost the UK economy up to GBP 1.9 billion -- among the most damaging cyberattacks in British corporate history; some investigators have since raised the possibility of Russian state involvement or tacit support, though attribution remains contested. ShinyHunters is documented via a year-long (mid-2025 to mid-2026) phone-based (vishing) campaign against Salesforce customers, tracked by Google Threat Intelligence Group/Mandiant under clusters UNC6040 (initial access), UNC6240 (extortion), UNC6395 (the August-September 2025 Salesloft/Drift OAuth token theft, the larges
Target sectors: government administration, automotive, retail, finance, education, technology, saas, telecoms, entertainment, legal, healthcareadjacentkyc
Target regions: North America, Europe, united kingdom, Latin America, mexico
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1590, T1598.004, T1583.006, T1588.002, T1588.007, T1566.002, T1199, T1059, T1059.001, T1078