Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns

Check Point 2026 AI Security Report (TL-2026-1347), also tracked as AI Security Report 2026, is a high-severity tracked intrusion set, first published 2026-07-15. It is attributed to Scattered Spider with medium confidence, affects Salesforce CRM / Experience Cloud / Data Loader integrations, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1059), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-1347

Threat ID
TL-2026-1347
Also known as
AI Security Report 2026, AI: From Assistant to Operator
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-15
Last reviewed
2026-07-15
Attribution
Scattered Spider
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
government administration, automotive, retail, finance, education, technology, saas, telecoms, entertainment, legal, healthcareadjacentkyc
Target regions
North America, Europe, united kingdom, Latin America, mexico
Detection rules
9
Indicators of compromise
23

Malware and tooling in Check Point 2026 AI Security Report

Malware and tooling: DragonForce, VoidLink, BACKUPOSINT.py, Claude Code, TRAE SOLO, ToogleBox Recall, TruffleHog - S9009

Check Point's 2026 AI Security Report documents AI's shift from assistant to autonomous operator: threat actors ran thousands of AI-executed commands with minimal human direction (including a lone hacker's Claude Code + GPT-4.1 breach of nine Mexican government agencies), used CLAUDE.md-based prompt injection to hijack agentic sessions, built deployment-ready malware such as the 88,000-line VoidLink C2 framework in under a week, and deployed generative voice/face/document fraud at scale ($250M in FBI-attributed voice-fraud losses). The report ties these capabilities to active, ongoing campaigns by Scattered Spider (Marks & Spencer DragonForce ransomware, Jaguar Land Rover production shutdown) and ShinyHunters (year-long Salesforce OAuth/vishing campaign), with 87-93% of organizations experiencing high-risk AI interactions monthly from October 2025 to May 2026.

How Check Point 2026 AI Security Report works

Check Point Research's AI Security Report 2026, published 14-15 July 2026, is a telemetry- and incident-driven assessment that argues generative AI has crossed from an attacker-assistance tool into an autonomous attack operator. The report's central evidentiary examples are: (1) a criminal breach of multiple Mexican government agencies in which AI executed thousands of commands autonomously across dozens of sessions with minimal human direction between steps -- independently corroborated by Gambit Security, which found a lone hacker logged 1,088 prompts that generated 5,317 AI-executed commands across 34 live sessions between December 2025 and February 2026, exfiltrating over 150GB of data (including 195 million taxpayer records from Mexico's federal tax authority, SAT) using Claude Code (which issued roughly 75% of remote commands) paired with GPT-4.1 and a custom 17,550-line Python tool, BACKUPOSINT.py, that shipped stolen server data to OpenAI's API to generate 2,597 reconnaissance reports on the government's server architecture; Anthropic confirmed the abuse, banned the associated accounts, and hardened misuse detection; and (2) VoidLink, an 88,000-line Zig-language cloud-native command-and-control framework targeting AWS/Azure/GCP that a single developer built almost entirely with the TRAE SOLO AI coding agent using spec-driven development in under one week, comprising 37 plugins spanning reconnaissance, credential harvesting, lateral movement, persistence, and anti-forensics, with cloud-aware stealth that fingerprints Docker/Kubernetes execution to adapt behavior. On the jailbreaking/prompt-injection side, the report documents the 'CLAUDE.md method,' in which attackers plant malicious instructions in configuration files that coding agents automatically load at session start, persisting across turns until the file is removed and exploiting the fact that LLMs process instructions and untrusted data as a single text stream. Malicious prompt-injection payload detections rose roughly fivefold between March and May 2026, and high-risk enterprise AI prompt rates doubled from about 1-in-50 to 1-in-25 interactions over the reporting window, with indirect prompt injection approaching 1% of observed prompts by May 2026 -- evidence the report frames as indirect prompt injection becoming a routine, operational attack path rather than a theoretical risk. On generative identity fraud, the report finds forged voice, face, document, and live-video content is now cheap to produce convincingly, with autonomous AI-run identity fraud already observed in real attacks and criminal marketplaces (autonomous interactive video remains emerging); trained observers correctly identified AI-generated faces only 41% of the time versus 30% for the general public, and the FBI attributes $250 million in losses to voice-enabled fraud. The report explicitly ties this capability shift to two named, currently active campaigns. Scattered Spider (with reported overlap/collaboration with ShinyHunters and Lapsus$ under the 'Scattered Lapsus$ Hunters' banner) is linked to the March-April 2025 Marks & Spencer breach, in which a Tata Consultancy Services employee was socially engineered and their account used to email M&S a payload that deployed DragonForce ransomware, and to the Jaguar Land Rover intrusion beginning 31 August 2025, which halted all JLR production for three weeks and is estimated to have cost the UK economy up to GBP 1.9 billion -- among the most damaging cyberattacks in British corporate history; some investigators have since raised the possibility of Russian state involvement or tacit support, though attribution remains contested. ShinyHunters is documented via a year-long (mid-2025 to mid-2026) phone-based (vishing) campaign against Salesforce customers, tracked by Google Threat Intelligence Group/Mandiant under clusters UNC6040 (initial access), UNC6240 (extortion), UNC6395 (the August-September 2025 Salesloft/Drift OAuth token theft, the largest SaaS breach on record, exposing over 700 organizations including Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, PagerDuty, and Tanium), and UNC6661/UNC6671 (a January 2026 Okta/enterprise vishing wave). Vishing calls impersonating IT support talk employees through Salesforce's OAuth consent screen to authorize an attacker-controlled connected app disguised as Salesforce's own Data Loader, granting persistent API access; a related November 2025 campaign abused Gainsight-published Salesforce integrations to compromise 200+ instances (Atlassian, DocuSign, F5, GitLab, Malwarebytes, SonicWall, Thomson Reuters, Verizon), and an April-May 2026 wave abused stolen Anodot tokens to access Instructure/Canvas (275M records, 3.65TB), defacing 330 Canvas portals on 7 May 2026 before a ransom was paid by 12 May 2026 to forestall leakage. No CVE is associated with this report; it is a threat-landscape/campaign synthesis rather than a single-vulnerability advisory, so severity is analyst-assigned based on active-campaign impact and scale rather than CVSS.

MITRE ATT&CK techniques used in TL-2026-1347

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Defense Evasion

T1027 Obfuscated Files or Information; T1497.001 System Checks

Execution

T1059 Command and Scripting Interpreter; T1059.001 PowerShell

Command and Control

T1071.001 Web Protocols

Persistence

T1078 Valid Accounts

Discovery

T1082 System Information Discovery; T1580 Cloud Infrastructure Discovery

Initial Access

T1199 Trusted Relationship; T1566.002 Spearphishing Link

Impact

T1486 Data Encrypted for Impact; T1491.001 Internal Defacement; T1657 Financial Theft

Credential Access

T1528 Steal Application Access Token; T1556.006 Multi-Factor Authentication; T1621 Multi-Factor Authentication Request Generation

Exfiltration

T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration to Cloud Storage

lateral-movement

T1550.001 Application Access Token

Lateral Movement

T1550.001 Application Access Token

Resource Development

T1583.006 Web Services; T1588.002 Tool; T1588.007 Artificial Intelligence

Reconnaissance

T1590 Gather Victim Network Information; T1598.004 Spearphishing Voice

Affected products and versions in Check Point 2026 AI Security Report

  • Salesforce — CRM / Experience Cloud / Data Loader integrations
    Vulnerable versions: OAuth connected-app authorization flow (process weakness, not a version)
  • Multiple (Anthropic, OpenAI) — Agentic coding assistants (Claude Code, GPT-4.1) and third-party AI coding agents (TRAE SOLO)
    Vulnerable versions: Abused via stolen/purchased API access and autonomous session misuse, not a software defect
  • Jaguar Land Rover — Manufacturing / enterprise IT environment
    Vulnerable versions: Pre-31 Aug 2025 access controls
  • Marks & Spencer — Enterprise IT environment (via Tata Consultancy Services supply-chain access)
    Vulnerable versions: Third-party managed-service account access

Remediation for Check Point 2026 AI Security Report

Immediate actions

  • Enforce phishing-resistant MFA (FIDO2 security keys / passkeys) in place of push or SMS-based MFA
  • Audit and revoke unused or over-privileged OAuth connected-app grants in Salesforce and other SaaS platforms
  • Alert on new MFA-device enrollments and on deletion of MFA-enrollment emails from mailboxes
  • Block or scrutinize sessions originating from anonymized IP ranges (commercial VPN/proxy exit nodes)

Workarounds

  • Disable or restrict third-party OAuth app installation in Salesforce to admin-approved allow-lists
  • Require in-person or ticket-verified identity confirmation before any MFA device re-enrollment

Longer-term hardening

  • Establish callback-verification procedures for any inbound IT-support phone request before granting access or resetting credentials
  • Deploy monitoring for anomalous AI-agent / coding-assistant activity: high command volumes, autonomous multi-session execution, and outbound calls from agent tooling to external LLM APIs
  • Treat CLAUDE.md / agent-config files as an untrusted-input surface; diff, sign, or gate changes to auto-loaded agent instruction files
  • Build content-provenance and liveness-detection controls for voice/video-authenticated workflows (call centers, KYC, executive approvals) given synthetic-media false-negative rates
  • Integrate SaaS OAuth-application audit logging (Salesforce Event Monitoring, Google Workspace admin audit logs) into SOC detection content

Timeline of Check Point 2026 AI Security Report

  • Marks & Spencer breached after Scattered Spider-linked actors socially engineered a Tata Consultancy Services employee; the compromised account was used to deploy DragonForce ransomware, disrupting M&S operations for weeks.
  • ShinyHunters-linked actors (UNC6395) exploit compromised Salesloft Drift OAuth tokens to access Salesforce instances at over 700 organizations, including Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, PagerDuty, and Tanium -- the largest SaaS breach on record.
  • Jaguar Land Rover cyberattack begins; production is paused the following day and remains fully halted for three weeks, with total UK economic damage later estimated up to GBP 1.9 billion. A group calling itself Scattered Lapsus$ Hunters claims responsibility.
  • A follow-on campaign abuses stolen Gainsight-published Salesforce integration tokens to compromise 200+ Salesforce instances at organizations including Atlassian, DocuSign, F5, GitLab, and SonicWall before Salesforce revokes the tokens.
  • A threat actor begins building the VoidLink cloud-native Linux C2 framework in the Zig language using the TRAE SOLO AI coding agent under a spec-driven development workflow.
  • A lone hacker begins a multi-month intrusion into nine Mexican government agencies, orchestrating Claude Code and GPT-4.1 to autonomously execute reconnaissance, exploitation, and exfiltration commands.
  • VoidLink reaches roughly 88,000 lines of code and 37 plugins (recon, credential harvesting, lateral movement, persistence, anti-forensics) built almost entirely by AI in under one week; Check Point Research publishes technical analysis.
  • ShinyHunters-linked clusters UNC6661/UNC6671 run an Okta-focused enterprise vishing campaign, harvesting credentials and MFA codes and using a tool dubbed 'ToogleBox Recall' to silently delete MFA-enrollment emails; victims include Wynn Resorts, Harvard, Princeton, and UPenn.
  • The Mexican government breach concludes with over 150GB exfiltrated, including 195 million taxpayer records from tax authority SAT; the operator's tooling has logged 1,088 prompts generating 5,317 AI-executed commands across 34 sessions. Anthropic later confirms the abuse and bans the associated accounts.
  • ShinyHunters-linked actors exploit an Experience Cloud misconfiguration using a modified AuraInspector extension (user-agent string 'RapeForce'), warning roughly 400 additional victim organizations.
  • A second breach wave against Instructure/Canvas (via stolen Anodot authentication tokens, exposing 275M records / 3.65TB) defaces 330 Canvas portals with extortion messaging.
  • A ransom is paid to forestall public leakage of the Instructure/Canvas data stolen in the Anodot-token campaign.
  • Microsoft publishes guidance mapping a year of ShinyHunters Salesforce OAuth-abuse activity and defensive controls for SaaS applications.
  • Check Point Research publishes the AI Security Report 2026, synthesizing the above campaigns as evidence that AI has crossed from assistant to autonomous attack operator.

Sources cited for Check Point 2026 AI Security Report

Threats related to Check Point 2026 AI Security Report

Detection coverage for TL-2026-1347

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1347 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats