Google Reports AI-Powered Hacking Has Reached Industrial Scale
Google's threat intelligence group reported that AI-powered hacking escalated from a nascent problem to an industrial-scale threat in just three months. Criminal groups and state-linked actors from China, North Korea and Russia are using commercial AI models including Gemini, Claude and OpenAI tools to refine and scale attacks. Anthropic declined to release its Mythos model in April 2026. Google disrupted a criminal group on the verge of leveraging a zero-day vulnerability for mass exploitation using an AI large language model.
AI-powered hacking escalation
▪AI enables threat actors to test their operations, persist against targets, build better malware and make many other improvements.
▪John Hultquist, chief analyst of Google's threat intelligence group, stated that threat actors are using AI to boost the speed, scale, and sophistication of their attacks.
▪Google's threat intelligence group reported that AI-powered hacking has gone from a nascent problem to an industrial-scale threat in just three months.
Criminal group exploitation
▪The criminal group conducting the mass exploitation campaign appeared to be using an AI large language model that was not Mythos.
▪Google's report found that a criminal group was on the verge of leveraging a zero-day vulnerability to conduct a mass exploitation campaign.
State-linked cyber actors
▪State-linked actors from China, North Korea and Russia are widely using commercial AI models including Gemini, Claude and tools from OpenAI to refine and scale up attacks.
▪Google's report found that groups were experimenting with OpenClaw, an AI tool that went viral in February 2026.
Anthropic Mythos model withholding
▪Anthropic declined to release one of its newest models, Mythos, in April 2026 after asserting that Mythos had extremely powerful capabilities and posed a threat to governments, financial institutions and the world generally if it fell into the wrong hands.
▪Anthropic stated that Mythos had found zero-day vulnerabilities in every major operating system and every major web browser.
▪Anthropic said Mythos's discoveries necessitated substantial coordinated defensive action across the industry.
Defensive cybersecurity capabilities
▪Steven Murdoch stated that the old way of discovering bugs is gone and it will now all be LLM-assisted.
▪OpenClaw is an AI tool that offers users the ability to hand over large chunks of their lives to an AI agent with no guardrails and an unfortunate tendency to mass-delete email inboxes.
▪Steven Murdoch, a professor of security engineering at University College London, stated that AI tools could help the defensive side in cybersecurity as well as the hackers.
Public sector productivity skepticism
▪The Ada Lovelace Institute recommended supporting longer-term studies that measure productivity gains over years rather than weeks.
▪The Ada Lovelace Institute report stated that productivity estimates shaping major government decisions about AI sometimes rest on untested assumptions and rely on methodologies whose limitations are not always appreciated by those using figures in the wild.
▪The UK government has estimated a £45 billion gain in savings and productivity benefits from public sector investment in digital tools and AI.
▪The Ada Lovelace Institute published a report on May 11, 2026 cautioning against assumptions of a multibillion-pound public sector productivity boost from AI.
▪The Ada Lovelace Institute recommended encouraging future studies to reflect uncertainty over the impact of AI technology.
▪The Ada Lovelace Institute recommended ensuring government departments measure the impact of AI programmes from the start.
▪The Ada Lovelace Institute stated that most studies of AI-related increases in productivity referred to time savings or cost reductions, but did not look at outcomes such as better services or improved worker-wellbeing.
Perspective of AI safety researchers and regulators
▪Anthropic stated that Mythos had found zero-day vulnerabilities in every major operating system and every major web browser.
Perspective of Cybersecurity defenders
▪Steven Murdoch stated that the old way of discovering bugs is gone and it will now all be LLM-assisted.
▪Steven Murdoch, a professor of security engineering at University College London, stated that AI tools could help the defensive side in cybersecurity as well as the hackers.
Story comments
Loading comments…