Cyber Security News

Anthropic’s Mythos AI Model Reportedly Breached NSA Classified Systems in Hours

Anthropic’s flagship Mythos AI model reportedly infiltrated nearly all of the National Security Agency (NSA) ‘s classified systems within a few hours during an authorized red-team evaluation on June 11. This incident now seems to be the main reason for a broad U.S. government directive on export controls issued the following day.

Senator Mark Warner, Vice Chairman of the Senate Intelligence Committee, disclosed that General Joshua Rudd, who simultaneously leads the NSA and U.S. Cyber Command, told him directly that Anthropic’s Mythos model “broke into almost all of our classified systems, not in weeks, but in hours.”

The statement, first reported by The Economist, has not been formally confirmed by any government agency, but has rapidly reshaped the narrative around Washington’s decision to pull Anthropic’s two most advanced models from public access.

The disclosure recontextualizes the June 12 Commerce Department directive, which barred every foreign national, including non-citizen employees within Anthropic itself, from accessing Fable 5 and Mythos 5.

Anthropic subsequently suspended both models for all customers. Crucially, this marks the first time the United States has applied export controls directly to an AI model rather than to the hardware or chips powering it, a landmark regulatory precedent in AI national security governance.

Allied governments within the Five Eyes intelligence alliance, including Australia, Britain, Canada, and New Zealand, were reportedly caught off guard, with permissions for government agencies, banks, and major firms revoked without prior warning.

Anthropic disputes the government’s stated rationale. The company contends that the cited trigger was a narrow jailbreak one that other leading models, including GPT-5.5, also exhibit and characterizes the wholesale recall as a disproportionate overreaction.

In Anthropic’s account, the flagged behavior amounted to asking the model to analyze a codebase and fix identified issues, not a genuine autonomous offensive intrusion. The company is actively working to restore access and is preparing a collaborative risk management framework with the White House.

What Features Should AI SOC Have? – Download Free 2026 AI SOC Features Checklist

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago