When Critical AI Functions Suddenly Disappear
Earlier this year, a US export-control directive took Claude Fable 5 and Mythos 5 offline for every customer worldwide, with no warning and no transition window. Access returned 19 days later, but the chats and tokens lost in between did not. Max, Cody, Seth and Aidan work through what that means for anyone whose daily workflow now runs through a single AI vendor. Also in this episode: the AI exclusions that are quietly starting to appear in commercial security policies, plus a high-profile data breach that impacted nearly 7 million people.
WATCH / LISTENA round-table on the security stories everyone's talking around. The panel takes the position most people won't say out loud, then argues it out. Part of Galactic's Threat Aware.
Transcript
Auto-generated transcript, apologies for any errors. Download as text
Narrator
This is Unauthorized Opinions, part of the Threat Aware Podcast Network, where the Galactic Security Team says exactly what's on their minds. Unfiltered takes on the cybersecurity threats, trends, and stories that matter most to the people defending real organizations. Now, here's your host, Max Kourick.
Welcome in. We are glad you're here. I'm Max Kurek, and this is Unauthorized Opinions, where we give you a Completely unfiltered view of the most notable happenings in the world of cybersecurity. If you're new here, welcome. If you're here from episode one, glad you're back. Joined as always by Seth Loe, Cody Kretsinger, and Aidan Brown. Guys, how are we feeling? Good as always. I've I love Cody's dance moves over there, so that got me going. I gotta keep Future montage. No. No. Yeah. Yeah. That's why we do this, is so that we can create reels just like that.
All right, guys. Today's episode is packed, so I want to get right into it. We've got to have a conversation about the recent re-release, unrelease, or I should say the recent release, unrelease, and re-release of Fable and Mythos. There's also something quietly happening around AI and cyber insurance that we'll tackle. And a large-scale data breach affecting about seven million people became public just the other day. There's some very interesting questions, I think, to discuss around the response and notification process. When you look at the timelines, especially, I think there's some questions we want to get into here.
And there's a high likelihood that somebody listening to this will be one of the impacted individuals from this breach. So definitely stay tuned for that. Before we get into those things though. We talked quite a bit last time, guys, about the recent news surrounding the Pentagon's decision to suspend CMMC phase two requirements, kind of leaving a lot of people hanging. So I wanted to ask all of you to get us started. And Seth, I'm going to come to you first on this. I wanted to ask you about compliance frameworks, since there are a lot of people out there that are scrambling a bit and trying to find a path forward in the wake of the CMMC news.
So Seth, you're standing up a security program from scratch at a new organization. There's no compliance mandates, no framework requirements per se that are telling you what you have to reach for. What framework are you building your security program on? What standard framework are you aligning to and why? Probably gonna go with hula hookah version two. It comes from a small island. In the South Pacific. It's mostly around security, around coconuts and grass skirts, but that no compliance requirements. That's my hands down on that. But if we're talking about real data, we're talking about real business, just because they put it in real terms, they got real specific with it, they didn't make it too long.
I mean I love me some NIST 800 171, but we're talking about a hundred security controls here. And that's out of the reach for a lot of organizations. I'm gonna go with FTC safeguards. They put it in real terms, they basically built you a framework that says what to do. It's but it's a standard that starts where you gotta start, which is with an a realistic assessment of risk for that organization. Take a real look at the real risks your organization has faced and build your cybersecurity framework around that risk analysis using these recommendations. Safe to say there's a lot of best practices to draw from that framework, even for non financial institutions.
I mean, just about anyone can glean good insights from that, like you're saying, high level enough. And although FTC does touch a lot more industries and a lot more verticals than you'd think. Covered entities under FTC, if you look at the list, like there's a lot of companies out there that are thinking, I've got I don't have any FTC security requirements. Yeah, I looked into the handle of my toothbrush this morning and it said FTC compliant. It's everywhere. It is everywhere. It's there's money everywhere, so there's gonna be FTC safeguards everywhere. Okay, Cody, what say you, sir?
Same situation, same scenario. What are you choosing? You know, I like Seth's grass skirt comparison. Mine in that is and this is I'm reaching deep here. Gulla Gullah Island compliance standards. Classic. Yeah, it is a classic. No and being serious, so I was going to say the NIST Cybersecurity Framework. I was. And I think Seth had a really good point in the amount of controls that go along with that. And you know, at this point, I think everybody knows that I hate compliance to a certain degree. I'm just I'm not wired for it. That's just not it's again, it's not my lane.
So, you know, if I was standing up an organization and looking at the what framework to follow, my gut was the NIST cybersecurity framework. And it just because of how in-depth it is. And I realized the challenges with organizations that happens, right? So or what happens when there is that many controls and the challenges for organizations. So that got me thinking when Seth was talking, you know what? If I wanted a practical framework from an attacker's perspective, I would actually use OWASP. So OWASP has got a really good set of top tens that they use for not only web applications but for like ai and stuff like that.
I think those are pragmatic approaches to things that could be used in a smaller environment or a new environment that are easily approachable. And there's you know a long storied history on why OWASP does these things or categorizes these things in such a way that they do or prioritizes them in such the way that they do. So but my answer's gonna be the OWASP top ten across the board. I think a lot of organizations don't remember that exists out there and could apply to them. Everybody loves a top 10 list, top five list, you know, like the viral content.
So shout out to OWASP for making their frameworks in a format that everyone, you know, there's some viral capacity to that. Okay, Aidan. Same question, sir. What do you got? Yeah, I just knew Cody was gonna go I was debating either OWASP or if he was gonna t mention the miter attack framework. But I mean my mind I will I'd be lying if I said my mind didn't go to the NIST CSF as well. And the reason it did and I s even though it can be complicated as Cody and Seth said I do still think it being it can be good in more so like a governance aspect because I like how it boils it down.
It doesn't there's not a bunch of fluff language in it. So when say we're the security practitioners in this case, if I'm going to the board, if I'm going to the CEO and I'm listing off a bunch of if I start going through maybe FTC or all of these, all of this complex language and some of these standards that we see. I think N Nis CSF does a good job at boiling it down, cutting the fluff. And so when you take it to those board members, to that CEO, it's a lot easier for them to understand.
But I'm gonna cheat a little bit. And I'm also gonna say that I would try to include some something from the CIS. So fr something from CIS, whether that be the I believe it's called the critical security controls. And also I love all of the benchmarks that they put in. So When going back to the NISCSF, that's the governance side. That's what you t tell the board. Then once you get sign off, once you get the approval for some of the controls you talk about, those CIS benchmarks can really help you configure, implement those things.
So I know I cheated a little bit there, and maybe that was not a part of the rules, but I love CIS and what they do though over there. We allow subtle cheating. We allow subtle cheating here. Go ahead, Seth. I was saying, and he pulls out the governance card too. Yeah. Makes us all look like amateurs. The one thing that'll lock in, Aidan, that I think you identified is first the maturity of the cybersecurity framework. And I think everybody here agrees, like, my goodness. But also the fact that you need a degree in reading NIST articles to be able to interpret them.
And the actually the crosswalk between them and using CIS as controls and all of those gives you language actually that makes it a lot easier to understand. And there's a lot of folks that don't realize that there's a lot of parallels between those two things. And that's actually that's a really good thing to call out. I just I wanna throw that in there because a lot of folks they Seth and I included, clearly, looked at from just one perspective and you threw out such a unique perspective on that I want to make sure that folks realize that that's a really solid way of approaching not only compliance but also governance.
Governance. The one thing I will say just because the you said like reading some of these standards, as everybody knows, can be an absolute snooze fest. And you gave me the idea I'm about to have a kid here soon. I think I'm gonna use HIPAA as the bedtime story. I think that'll put him to sleep real quick. Put him right to sleep. Yeah, I heard that if you dump the NIST framework into Claude, it just sends you the middle finger emoji back in the window. Doesn't even want to read it. Another good regulation to read your kid, Aidan, is Sarbang's Oxley.
It'll put you to sleep too. I'll keep that in mind. Yes. And then your wife will take an adorable picture of you passed out in the chair with a book or a thousand page PDF, I guess. With your baby sleeping soundly. That'll be so adorable. Wasn't that like a CDW commercial back in the nineties or something where Probably and then the technician routes the network cable to the switch? Yeah, that's that sounds about right. So and if anybody if you have a different answer to this, definitely let us know because we're all ears, but I think those are some good answers and some good ways to get us started.
And if you're in the CMMC unsure what to do boat, I need I just need to base my security program on some type of standard framework. Those are some good places to start. And I'll say for organizations that don't have explicit compliance pressure, it still makes a ton of sense to have a framework aligned security program, something to actually base. Your technical and administrative controls on it makes it way more defensible, way more organized. And so we're we don't we no longer live in the land where you have to have explicit compliance pressure to align to a particular security framework.
And I think all of those answers help tick that box for folks. Okay, let's get into something I don't even more fun. Like this is a bombastic Topic that we're getting into today. And it's something that I I'm sure everybody listening is familiar with on some level. And the thing I thought when I was bringing this forward was, golly, what an appropriate name Fable has, because this has been such a freaking saga, man. And so guys, I'll set the stage here, and then I just want your very like off the cuff reaction to this entire sequence of events.
And then I've got some I got some more targeted, a couple technical questions, a couple of like ethical questions that I want to get into around this. But just give me your gut reaction. So at the beginning of June, June 9th, we're currently in the month of July, but in on June 9th, as the first publicly available model in its Mythos class tier anthropic launch Fable 5. And the company at the time, I think, described it as carrying the strongest safeguards ever applied to a commercially deployed model. I think that was kind of the marketing spin.
And then Mythos five at the same time was live but remained gated to at that point an even smaller number of vetted partners than we're sitting at today. But three days after the launch of this, I think that was June 9th, on June twelfth. The Commerce Secretary sent a letter to the CEO of Anthropic ordering that they suspend both of the models for any foreign national anywhere in the world, including this is crazy, Anthropic's own non-U.S. Employees. So talk about promoting business and productivity. And the stated trigger, the reason why. Was a jailbreak technique discovered by Amazon researchers.
No conflict of interest there, that could allow the model to read a code base and surface software vulnerabilities. The rest of the story here, right? Anthropic complied within hours. They took both the models fully offline globally, not just for the groups that the Commerce Department had reached out to them about. But the company voiced their public disagreement with the decision. And argued that the jailbreak was narrow in scope and had not led to any documented harm, and that was already replicable by other commercially available models. I think they even very diplomatic of them said that this was all a misunderstanding and they were working to restore access.
And the last piece I'll throw into the mix here is that the suspension came against a broader backdrop of tension, I think it's safe to say. Between Anthropic and the federal government, because earlier in 2026, the government and the Pentagon specifically had pressured Anthropic to weaken its ethical guidelines. Imagine that, around autonomous weapons and mass surveillance, and kind of Anthropic had very publicly refused that. So there's definitely a history here. It's a little bit of a rocky relationship. Then last thing, on July 1st, 19 days after the suspension. Fable Five came back online and it kind of alongside a new industry-wide framework for classifying and communicating jailbreaks backed by all the big guys, right?
Amazon, Microsoft, Google, they were all kind of in support of this. And Mythos V access was restored as well. And I think the organization, the vetted partnership organizations actually grew, and I think it's like over a hundred now. So there's the saga. Cody, pick any part of that or the thing as a whole, and like you obviously read that like we all did over the course of whatever, call it thirty ish days, twenty to thirty days. Where was your mind at as all of this was unfolding? And like once the dust had settled, what was your biggest takeaway from the fable saga?
We're calling it. The fabled saga of fable. The fabled saga. I Listen, the first component of this, the jailbreak, is questionable at best. Like come on, there's an elephant standing in the room here and we've gotta call it out. The jailbreak, come on. Th there's a blog that I wrote just a few weeks ago around the fact that because of the way language works and large language models operate. There's always going to be a jailbreak. There's is it is a certainty. And for any AI aligned organization that might have some AI that they're trying to promote on their own to call out the leader when it comes to their AI saying, well, there could be a jailbreak in it.
Come on. Like, of course there is. But Th there's other things there's other components there that they can leverage in order to secure that, right? They don't need to take it offline. And in fact, I wanna hit on something I wanna hit on something, Max, that you y you didn't mention is that anthropic was labeled as a supply chain risk to companies, not just you know, you can't use it. The They qualified it as bad as like actual malware because they wanted them to pause it because of a potential jailbreak. So what is that what does my suspicion say?
Well, this is interesting. And I w what we have found since all of this has essentially been publicized is you have a number of CEOs and a number of AI folks That are in the industry and very much smarter than me. So I trust their judgment. That the jailbreak to begin with might have been just fabricated, or at least made to be bigger than it actually was. So that calls into question everything surrounding this. But what I do like at the very end of this, other than the fact that it is so much harder now to use Fable and to get it to do like cybersecurity research things.
The thing that I do like about this is there's a very clear way that I think AI companies have are responding to it and then giving support to anthropic and how they did it. And it's a shame. It's a shame that somebody threw a grenade over the wall to probably allow their own AI to catch up because they were jealous. And that's my hot take on it. Aidan, I want to come to you next, because you actually do a show that's part of the Threat Aware Podcast Network called Beyond Intelligence that's focused on just the world of AI.
So y this is kind of a this is kind of a story that I know really stood out to you in particular. What you got any hot takes for us, like Cody? I'll first I want to go back to what Cody said, kind of with the news that the jailbreak and that they're shutting down Claude and that whole fiasco of it getting unreleased. I the reason I bring it up after you talked about it, Cody, was because I'm pretty sure we were like in a meeting. Or before I even talk about that, like I think we were with our cybersecurity, our nerdy brains, we were kind of just waiting.
Like, when is that gonna happen? When you saw all of those, look at all the safeguards, all the guardrails we put up for Fable. We're all kind of thinking, okay, how long is that gonna last? And I we were in a meeting, me and you, Cody, and I forget if it was me or you and it was when that jailbreak like it was before they unreleased it. So one of us saw like, a jailbreak was released on GitHub or whatever it was, and we're like, like that was not surprising in the slightest. We're like, yeah, cool.
Because I think we were expecting it. So kind of on along that lines, I just going back to that day, it just wasn't surprising. And the thing I read this somewhere and I don't have the source. I wish I had the source. Because I don't look, I don't know if this source was vetted or not. But what it said, it was talking about how another of possible reason conspiracy theory alert that Fable was disabled. Unreleased, blah, was because what it found when it started going after these systems, like in the government, specifically, talking about what it found, the vulnerabilities, the weaknesses, whatever it may be.
And the government was like, Holy crap, this is too much. We gotta shut this thing down. And look, that's I know that's going along. Again, I wish I had the source. But when I saw that, I could see that as being a very real possibility of whoa, this thing is way more capable than we thought it was. And we don't have enough manpower to fix this right now, which is a another conversation, honestly, about AI and this mythos stuff, keeping up, keeping up with what it can find, how good it actually is. So when I read that out, that that's kind of where my head went.
Like it did its job. And people just didn't like what it found. I actually got read into this, by the way. I do know what it found. And within hours of launch, it found a photo of Jeff Bezos with a mullet in the late eighties. And somebody at Amazon printed it out and stuck it over the water cooler. And Bezos called his buddy, Stephen Miller, and said, You got to shut this down. You gotta shut this down. Nobody was supposed to ever find that picture. I mean I thought mullets were kind of back in. Do not Google Ceflow Mullet, please.
As in please do. We have we may have a future nominee for the Security Hall of Shame if anyone successfully finds the Ceflow Mullet picture. If you find it in my defense, achy breaky heart was a thing. And nobody, none of us thought we had mullets. Because that man existed. We all feel Billy Ray still has a mullet, I think. Billy Ray was the mullet and we were all fine. And I look at it now, mm, not enough party in the back, not enough business up front. But I was style is circular, right? It all comes back around.
I know people are giving these to their kids. I'm stopping strangers on the street and say, Why would you do this to your child? And anyway. I saw a kid at a baseball game a couple months ago with a rat tail. I haven't seen a rat tail in a minute. Seen the Phantom Menace. That yeah, good point. Future Jedi. This is wow. Two Star Wars references in two episodes. We're on a roll here, bro. Okay, Seth, but I do want to come back to you just kind of for your hot take and your overall reaction to this fate fable saga.
Yeah, I think so my hot take was I had a few tokens to spare. And I said, Let me throw something really big at this. Right. And I was, I said, I want to, I want you to do this massive research project. I'm going to hinge a major piece of production on it. I want to see the best you can do. I really want to see if this is better than Opus. And it got all that work done. And I don't know if you guys noticed this, but my deadline was the next day, the day they shut it down.
And you could not go back to those chats and get the information out of them. It was gone. It just said this model's no longer available because of Bezos' mullet picture. And I can't give you this information anymore. I lost some productivity there. I burned a bunch of tokens and I had to start. I actually I got in trouble for burning tokens on that model. But the other thing that I will say, Max before I give it over to you because I forgot about this and this is a thing that I do want to bring up, is that there are other models out there that do not have guardrails.
Period. They're it that are accessible to folks that are used for nefarious things. That you can run locally in your own consumer hardware. And yet here we are regulating an AI company for actually putting forward fairly innovative stuff in order to better secure things. Because at the end of the day, right, the more security researchers find or the more the model finds and vulnerabilities. Hopefully the faster we are at fixing those things because that is a positive thing because. The bad guys are still going to leverage AI to find the ways in. With there's no sense in stopping it.
You're just delaying the inevitable, or you're giving the ability to the threat actors while stalling. And it's just it was a misstep. The whole thing's was misstep. Yeah, and that point about other models without guardrails kind of highlights the aspect of the story we kind of talked a little bit about that earlier disagreement, maybe you'll call it, friendly disagreement that the federal government anthropic had earlier in the year. Maybe there's a little bit more to that aspect than we've even gotten into here. But I'll leave that for the listeners to draw their own conclusions on.
I do want to wrap this discussion with a practical question. And this goes a lot into this is a business continuity question, and it has a lot to do with how you're managing the reliance that your business has on these types of models because every customer on the platform lost access overnight, right? Without any warning, without any transition window, like nothing, like Seth was just talking about, right? All those tokens wasted, all that productivity lost. So what's the lesson here? And Seth, I'll come to you first on this. What's the lesson here for companies about how to architect their AI dependencies going forward and like what you need to be thinking about considering I mean, I'm prognosticating here, but something tells me, right?
This isn't gonna be the only example of this ever happening in the history of AI deployment. So like what do cybersecurity professionals business leaders, MSPs who are serving clients like need to be thinking about when it comes to managing the entire risk profile, including the business continuity risk that AI is having on their organization. Yeah, I for me this was a lesson in the ability to be flexible and not be dependent on any one model or any one provider. Right. And we know this lesson works on a macro scale too, because Okay, a lot of people right now, I mean, in and this is what, July the fifteenth, twenty twenty six, that we're having this conversation and people are anthropic, anthropic, anthropic, anthropic, this back and forth and this.
We know that a year from now it's probably gonna be somebody else's model that we're talking about. It's gonna be some upstart that, you know, they have internal strife and fifteen of their employees branch off and do their own AI and now everybody's on that or whatever. Whatever happens in the business community nowadays. But I think that On a small scale, had I been more diligent about continuously keeping a handoff file, like you should be doing when you're doing big projects, you should periodically pause in the middle of a project and have your model build you a handoff file that includes a log of everything that you've done in case something happens and you have to pick it up from another chat because you ran out of tokens for that conversation, or there's a problem, you know, if you're working with a desktop.
Device and you run into a problem on your computer, you know, being able to pick that up. But I think it really is about they can't get so enamored and fascinated with the new world of AI that they don't remember just basic IT. Just basic good IT. Back it up. Make it redundant. Don't be too reliant on one system. Be willing to flex. Be able to flex. When the conditions ask for it. So I think all of that holds. And Aidan, coming over to you, anything else that you would add, because I mean this is a real thing that a lot of organizations are not thinking about today.
I can almost guarantee it, right? Like it's we're still so enthralled and so in awe of what AI is able to do to transform our business that we're not thinking of the negative side of that coin or what could potentially happen to impact our productivity and impact our bottom line. Yeah, I love how you put this question in a business continuity because that's what it is. And my mind went straight to kind of what Seth was saying there at the end, like and I'm not even going to go as far as to say like, what if something like this happens against where Fable, they just completely disable a model, anthropic goes out of business.
Open AI goes out of business, whatever it may be. I'm gonna say Just when because it's happened multiple times, as we know, where just there's a little bit of downtime where Claude just isn't working right now because something on their end, whether it be AWS, I don't know, where you just can't connect, you can't chat with Claude. And for business, that can be catastrophic. That just slight little downtime if you're not planning these things correctly, if you're not thinking in that business continuity mindset. Because I feel like Nowadays people are going so much, okay. We have to AI, AI.
We gotta AI this task, we gotta AI this task, we gotta AI that task, which don't get me wrong, I'm all for. I love AI, automating, especially the simple tasks, to focus on more complex tasks that us humans can do, I guess you could say. But what I'm why I'm saying that is because I feel like businesses can get in a fault where they're so reliant on AI doing tasks for their work that when Claude or whatever it may be goes down, or like I said, the this other instance where a model gets completely taken out, that completely disrupts.
It turns into almost a disaster for their business. That's where I this again, that bin business continuity mindset of backups, redundancy, not so reliant on AI to do stuff. Humans remembering how knowing how to do a certain task, not just AI, is so important because when that downtime happens, you don't want a disaster happening. It's a great point and a perfect time before I throw it over to Cody because I know he's got some thoughts on this too. That remember Business continuity and disaster recovery is distinct from incident response. Right? Like, like they are two distinct things.
And if not only should you be revising all of your procedures and your administrative controls around both of those things to incorporate the AI aspect. Like that is something where if you're renewing your incident response plan and it hasn't been touched in a year or two years, it could very well be missing some of these critical components. But it's also the reason why. Those are such distinct things because there's no security incident here that occurred. Right. Like Fable wasn't taken offline because some threat actor group in Russia like completely destroyed it. This is 100% a business continuity issue.
And the planning for that needs to happen outside of the way you typically will think about incident response. So I think it's a good call out, Aidan. Cody. What would you say for some of these organizations to make sure that they're mitigating the risk around interruption in any type of service or ability with their AI dependencies? Actually I think you three hit it right on the head and Max, just a moment ago you said if you haven't revisited your incident response policy or procedure in the last year or two, you'll you likely haven't taken into consideration any of these things.
I would say that is a certainty because this is a brand new thing. That is coming out. The only other thing that I'll kind of put in perspective here is, you know, when we talk about business continuity, when we talk about all of these things, about redundancies, backups, and things along those lines, what we're doing is we're looking at the risk to the organization, the overall risk to the organization if something were to occur. And I think that there's For a lot of organizations, they like to put them in buckets like an incident, right? Is that really a risk?
Well, yes, it's a risk. That is a risk that I have to own or I have to shove off to someone else. And ideally, right? You want somebody else to take on that risk so that way you don't have to deal with it. And I think with this particular thing with AI, as well as a whole laundry list of other things with AI, we're looking at a landscape now that is changing incredibly when it comes to risk and AI itself. So that's just where I'm at. I would get the record to show that Cody was the first one in this podcast to tell someone to shove off.
First, but almost certainly not the last. So we'll have to we'll keep a running tally of that. But it is it's a really good segue into the second pieces and we'll kind of go rapid fire on this one. Because when we're talking about mitigating AI risk, there's something that's kind of been happening for the past eight or so months to one of those primary risk mitigation components for a lot of businesses, and that's insurance. And specifically, there's some major insurance carriers that have been quietly filing for exclusion clauses in their standard commercial liability policies to keep AI.
Out of those policies. And that's really been happening actually since late 2025. If you're if you've got policies through Berkshire or through Chubb or for or through Travelers, this is something to note because state regulators have actually approved more than 80% of these filings for exclusions from these companies. Florida, Connecticut, Maryland, those are the states that are having that are seeing the highest volumes of these exclusions. So it it's It is a cyber insurance, not necessarily AI aspects to commercial liability insurance, but cyber insurance is something that we talk about as being a virtual must-have at this point in your security program and in your risk management structure.
And with the way AI is increasing risk around all around so many areas, these types of insurance policies that include AI coverage are things that organizations have been looking for. More and more, and quietly these insurance companies have been stripping out of their policies more and more. A couple of stats to throw at you guys, and then I'll and then I've got a question for you. AI related litigation has surged 140% year over year in 2025. And there's a an actual a report from Gallagher and MIT that documented a 978% increase in generative AI lawsuits between 2020 and 2025.
So, like there's a reason, right, why these insurance companies are kind of going this way because obviously the market is shifting and the risk is increasing exponentially. But there's real impact here for organizations because we were just talking about revising incident response policies and business continuity and disaster recovery policies. What about? Reviewing and renewing your insurance policies because most organizations that are deploying AI tools have not audited whether their existing policies cover AI related incidents. Some have, and if you have, give yourself a pat on the back because you're a little bit ahead of the game on this.
So my question for you guys is like in light of this news, and I'll hit each of you on this, how urgent is that gap right now? Right, where And who is really responsible for closing it? Is it the organization? Is it the broker? Is it the insurer? I mean, we kinda know that those last two, they're gonna be moving in the opposite direction. So we've kind of answered our own question. But how urgent is this gap and what would you tell people to do? Aidan, I wanna come to you first on this one. What do you think?
So The urgency question. I mean you said it right there. They're over eighty percent approval rates already for these clauses, I think you mentioned. Yeah. If that's not urgent, I don't know what is because it's saying these things are already happening. These clauses are already getting put in place. So when it comes to urgency, I'd say it's you have to get on it because it's happening, it's already there, it might already even be there in your policies. Without you even knowing about it. And that goes brings me to the second question, which I guess who's I think the question was who's responsible for finding this out?
Is it the organization? Is it the broker or the insurer? And you said to yourself again, the broker and insurers are there to make the most money that they can. And they're always going to find a way to make money themselves. So I would say unfortunately it's gonna be up to organizations, asking your brokers, asking your insurers, being like, Hey, can I see the policy? What do you have in it about AI? Do you have any exclusion clauses about AI within this policy that I need to worry about? So just having that conversation with them, asking the right questions, to figure out, okay, am I gonna after the fact find out, hey, my insurance policy doesn't cover this deep fake.
AI attack that just happened or does it not? So I would be proactive. I a lot of words are proactive versus reactive. If I were an organization, I'd be very much proactive when it comes to this. Yeah, I think this is something you needed to do yesterday or three, three or four weeks ago. Cody, Cody, what about you? I want to pump the brakes on the urgency just a little bit. Not at like the house is burning down. Like this is not a fire drill. This is a thing this is a regulatory change, or not a regulatory change, so this is an industry change in insurance.
And these things happen from time to time. That doesn't necessarily mean that it's not a big deal. In fact, it actually is a big deal. And I wanna highlight the specific stat that you used there, Max, a little bit earlier. A nine hundred and seventy eight percent growth in lawsuits from twenty twenty one to twenty twenty five. That is like that's nutso. That's a huge, huge thing there. And specifically the carve outs around AI driven employment decisions, IP violations from AI generated content, property damage to autonomous systems, all not being covered. Which, if you think about it, how many organizations probably use AI for some component of their like HR process right now?
It is not a small number. It's non zero, in fact. In the thing that I'll mention here is there's a lot of parallels to the way cyber was carved out initially. There's a lot of parallels to the way that cyber was carved out initially. Specifically, this it started to happen around 1997, and it took about 10 years for it to become more and more common. And it wasn't until 2017 when not Petya. If you remember the huge ransomware outbreak that happened around that time, it didn't really become commonplace in most policies to be a specific policy itself, an independent policy, until 2017, which is huge, which means it took 20 years for it to actually go from initial inception to actually being adopted by the industry as a whole.
There is a thing in Insurance right now, we're there's a thing in insurance right now that AI is running the exact same playbook. Specifically, they call it silent AI, and they're modeling it on the fact that we had specific cyber inclusions or separate cybersecurity policies that were built after the general liability policies. So that is a big long-winded way of me basically saying, yes, this was inevitable. And what we're seeing now is insurance responding to the risk the AI brings to organizations. So the carve out is first and then standalone policies is second. There's almost certainly going to be things down the road that are very similar to the cyber security components that are in cyber liability insurance.
You're probably going to see questionnaires. What AI are you using? Where are you using it for? What does it have access to? I think all of those things are coming. They are inevitable. And to come back to your original point, what should people do right now? And it's familiarize yourself with the fact that this is changing. Number one. Number two, look at that policy as is and whether or not those carve outs exist in it. Three, on renewal, look and see. How those risks change and where that risk owner ends up being, is it with the insurance company or is it with the organization?
And I think those three things coupled together in a calm, deliberate approach to how the review is done with the policy is the right way to look at it. I dislike ambulance chasing in terms of this stuff. I think it is big news, but I think we can have really good conversations with business owners around where that risk lies and let them understand who ultimately is going to own it. Yeah, if the insurance company can find a way to make a new skew to sell you, they're going to do it. And who doesn't love a couple extra cyber insurance forms to fill out every single year?
Seth, if any final thoughts? Yeah, I what was that nine hundred and eighty seven percent? Yeah I'll give you the example. Nine hundred and seventy-eight percent. Nine hundred over four years. I guarantee you, and everybody who's watched this podcast so far knows that my job is to say things that Tracy has to edit out later so that I have the only thing you see of me on this podcast is me going hi at the beginning and goodbye at the end. So the thing I'm gonna say is if you had polled me my senior year in high school and then polled me again my freshman year in college.
You would have seen a 979% increase in my love life. All right. Because it went from zero to like three. So we have to keep these stats in perspective a little bit that, like great point. You know, the ramp up for AI has happened in the last couple years. And billionaires gonna billionaire, right? This is the side, this is the insurance company's first move to get out ahead of having to ever pay out on claims around this, right? I mean, they know they're gonna have to pay out some, but I equate and you know, Cody's wisdom, Aidan's setup that for this was perfect.
Cody's wisdom on the what-to-do stuff. I could not agree with more. But what I was thinking about as he was speaking was when I was living in Florida in the 90s, and there was this series of storms that crashed into Florida, right? And they flooded areas of Florida that had never seen water before. And guess what? People didn't have flood insurance on their homes. And it was so widespread and so massive that the government came in and said to these insurance companies, nah, you're gonna cover it anyway. And I think that we are up for a flood of cybers cyber attacks that are launched by AI, that attack AI.
That attack every single software on the planet because what doesn't have AI built into it now? How can you write a cyber insurance policy when the app my calculator application has AI in it now, you know? And I think what's gonna hap what's gonna happen is we you know, I know there's a lot of doom and gloom out there. I do think there is a likelihood that this next wave of cyber this next wave of cyber attacks is not going to be one business at a time. It's gonna be mass massive hoo, that's easy for me to say, massive swaths of the planet.
And people that come together in organizations like governments are gonna say, nah, nah, thanks, thanks, you know, you're gonna have to cover this anyway, because our economy's gonna crash if you don't. Seth. I just want to say I prefer Microsoft Copilot in Notepad. And I love what they're doing with it and how much it sucks now. Right. Last Sherry on top of this too, just to tie it into what we were talking about earlier with the Mythos stuff, the CEO of Chubb named Mythos as a risk inflection point, you know, for This entire discussion when they were having the earnings call where they discussed these inclusion exclusions in the first place.
So that there's the tie-in for you. Okay, guys, last thing for this episode, and we're just I wanna highlight this as much for everybody so that you're aware of what's happening and you can do your due diligence on this. And then I want to ask Cody a little bit about the disclosure timeline around this, just from an incident response perspective. But if you didn't see the announcement just a couple of weeks ago, or not even. It was like last week, I want to say. And this is another thing, Aidan, that you caught in Threat Thursday, which is your weekly threat intelligence roundup.
Follow Galactic Advisors on LinkedIn or just go to GalacticAdvisors.com slash research and you can see all of this. But an attacker targeted a single employee of this company Assurance America and obtained their login credentials. The company Detected suspicious activity the following day and disabled the compromise credentials, terminated authorized sessions, all of the they put their incident response plan into place, which was good. But the forensic investigation that concluded in June, nearly three months after detection, and this is kind of what I want to come back to Cody on, confirmed that the attacker in that day that they had access.
Had copied files containing the personal data of nearly seven million people. And we're not just talking about names and contact information. There were driver's license numbers, there were social security numbers, there was auto insurance policy details, vehicle information, claims records. So there could be, you know, PHI and healthcare data in there as well. If we're talking about claims from serious accidents and things like this. And then Finally, on July 10th, customers started receiving notification letters about this, roughly four months between the attack and the affected individuals finding out. So my question, and Cody, the reason I want to come to you on this is because obviously this is a world that you've lived in for a long time and you've worked a lot of incidents, and some even at a scale like this, where So I guess my first question is the forensic investigation taking three months, probably not a surprise.
But I also want to ask you about the notification timeline here. And if it it's if it's indeed true that if there was a four month gap between d between the event occurring and letters arriving in the mailbox, what does that say about kind of the mindset of Assurance America and their approach to incident response communication in this case? So the This is there's a lot to unpack because there's a lot of question marks that aren't public, right? So we have to infer a few of these things. The timeline gives a lot of information without giving a lot of information.
The fact that they said that they responded within the first day is great. As you noted, right? The incident response policy and procedure was kicked off. That's absolutely wonderful. A forensics investigation, taking four months. Is a little faster than average, actually, when it comes to things like this. But the notification component is kind of where I'm drawing the weirdness. So usually there can still be components of the incident still going on when notification happens. It's usually on confirmed activity around regulated data. And as you mentioned, that was names, address, driver's license numbers, social security numbers, tax IDs, things like that.
So some significant risky information was taken or stolen. What it tells me is that an organization sat for a significant amount of time unable to make a decision. And that could be one of two things. That could be a leadership decision to take longer or more than likely to What occurred was the situation happened. The bad guys fished. They were able to get in with one login to get all of this information. I want to point that out that it was only one user that they had to fish in order to get into this system, which is just I mean, I could soapbox about MFA and FIDO keys for 30 minutes just on that.
But all of that aside, you have an organization that responded slowly. To making a critical decision, and that is notifying victims. And my suspicion lies in that the forensic investigation tied up so many critical assets that organization was more focused on getting back to the day-to-day and more than likely trying to figure out what actually they could still do than the than notifying, because those are two parallel things that happen. Have to happen during an incident, but when all of that information is stolen, obviously many people in leadership want to focus on did it actually happen?
And they should, but at some point the call's got to be made on whether or not we are notifying victims to a certain degree. So that being said. Seventy percent of organizations that go through an incident more or less fall into this category, meaning they just they get shocked. And only twelve percent of those organizations actually fully recover. I w those are huge stats. Like they actually get back to a good solid thing after the fact. So I think there's a couple of things to kind of take away from here. One is you had an organization that was stunned by this happening.
And paralyzed by the action, therefore they created more problems with inaction, and they likely didn't have some sort of priority in order to prioritize what systems needed to be used during an incident. And there's actually a fancy term for that now, and it's called minimum viable company, where you've identified what you actually need to do in order to survive during an incident. So They likely didn't have that. They were likely completely terrified and or stunned or paralyzed at the incident itself, and they just didn't know what to do. Yeah. Seven million people impacted by this.
They this is the largest breach, the largest known exposure of American driver's license data in twenty twenty six. Like was this incident. So Yeah. And I'd Max, real fast, I'd like to point out that driver's license numbers in many states are reversible. And there's information that is I'll say encoded in a driver's license number. Some of them still encode the last four digits of the social security number. How often do you use that for authentication? All the time. And Aidan, you wrote you actually wrote about this in your threat Thursday column last week. So I I'm curious for your take on this and especially the angle of like there's people listening here that are likely going to fall in this bucket of seven million impacted individuals.
Just some considerations for them, things to be thinking about, and kind of your takeaway from the write up that you did on this story last week. I mean, yeah, it the seven million driver's license Numbers. I mean, my Knolls is I'm having a hard time talking about it because in all honesty, like these unfortunately, the this size of breaches, I feel like have just become all too common. Like one of the things I tell people who are not cybersecurity or nerdy like me, when I talk to them about what I do, they'll ask me something like Well, what should I be worried about when it comes to cybersecurity or what is it about?
And unfortunately, like I tell them, I'm like, look, your data is most likely out there. It's most likely out there already. And that that's a tough pill to swallow for some people. And this is just another one of those stories. It's just another seven million driver's license number. And as Cody was saying, driver license numbers are not they're a direct identifier of somebody. It's not just like a zip code or a str a city that you live in. It's a direct identifier of somebody. So again, it that's just kind of where my mind went. It's just the unfortunate thing that's been that's become all too common nowadays.
And I'd love to hear Seth's thoughts, but I also I have a question for Cody as well. Let's be good at time. Seth, anything to add on this one? Yeah, I can confirm that driver's licenses in some states are reversible. I did the reverse hash on mine from Indiana and it just reverses to loser 1991. The I want to throw assurance America a lifeline here. I wanna throw a benefit of the doubt on them though. Cyber attacks related to AI infrastructure is something we're all adjusting to. Even top-notch forensics organizations. And I can't wonder that there wasn't some advice coming from that forensic organization that said, you know what, we cannot tell you how far this has gone yet.
And it could be dangerous for you to release that you are aware of this infiltration. It could get worse for you if the attackers find out that you know. So Little benefit of the doubt on there. But I'll pitch to Cody for Aidan's question. I want to come back to something that you said there, Seth. And you know, from a forensic standpoint, from an IR standpoint, there's always going to be some uncertainty as to what they uncover. And there are more cases than not where during an incident the IR team, the forensics team basically says, We don't there's no evidence to suggest that this happened, but they still have the data.
Right. Like it's very clear that they've got the data or there's something along those lines. And there's the logs don't exist or the forensic evidence, you know, is not conclusive enough to be able to draw the parallel. But what I would say is every organization needs to understand, like at some point, they have to decide whether or not that's the stake in the stand where they need definitive proof, or they're going to err on the side of caution, err on the side of their customers. Because the bad guys likely have the information. Am I gonna give them identity protection?
Well, I mean, thanks for my third subscription this year. I appreciate it. I think I'm covered. But also like the due diligence to actually protect your customers and have a heart to make sure that they have the things that they need in order to hopefully manage their identity. If that information is actually obtained by somebody and somebody uses it for something else. I just I would hate for organizations to want 100% proof before they act on anything. I think that's the wrong approach for organizations to take. And I know many organizations want to take that stance.
And I would as a recovering incident responder, I will say do not take that stand. That line is not worth crossing because it often has more negative impacts for the organization than it does positive ones. Yeah. Action taken when you didn't need to is so much better than action not taken when you needed to. And the end result proves that out every single time. I think that's a great call out. All right. I gotta wrap it there. Guys, thank you for being here for Seth Loe, Cody Kretsinger, Aidan Brown, my name's Max Kurek, reminding you to stay threat aware We will see you next time.