AI Access and Cybersecurity: Why North Korea's Interest in AI Stands Out

Apr 28, 2026 588 views

Recent events surrounding the unauthorized access to Anthropic's Claude Mythos model highlight a deeper issue in AI security—an issue that goes beyond typical cybersecurity concerns. Rather than solely viewing this incident through the lens of software security, it's essential to recognize the role of nation-state actors, particularly North Korea, in this evolving landscape.

Understanding the Incident

The breach occurred almost immediately after the public rollout of Mythos. Individuals were able to predict the endpoint of the model by leveraging Anthropic’s previous naming patterns. This situation originated not from a flaw within Anthropic's main infrastructure, but rather through a third-party contractor's environment. Observers noted that the group accessing Mythos seemed more engaged in research than malicious activities, yet the broader implications of such access cannot be overlooked.

A Structural Issue

Focusing solely on Anthropic's security practices misses the crux of the problem. The incident illustrates that controlled-access releases are inherently porous. Even if organizations establish solid access controls through legal means like contracts and non-disclosure agreements, these measures often fall short in practice. The reality is that each partner organization brings its own complexities, including various contractors and significant disparities in security hygiene, which creates a broader vulnerability that can be exploited.

The North Korea Factor

When discussing AI security, much of the policy conversation converges on the rivalry between the U.S. and China. However, the voice of North Korea—whose economic model relies heavily on cyber-enabled theft and illicit activities—remains conspicuously absent. While great-power friction captures attention, North Korea's immediate goals are straightforward: enhance productivity in its cyber operations by whatever means necessary.

Financial reports substantiate this. Research from the Insikt Group estimates that North Korea has pilfered approximately $3 billion from cryptocurrency exchanges through cyberattacks as recent as 2023. Further investigations from the Multilateral Sanctions Monitoring Team reveal that nearly $2.8 billion was stolen between early 2024 and September 2025 alone, with these funds reportedly funneled into weapons development.

Each cryptocurrency heist fuels the regime's military ambitions.

Why AI Models Like Mythos Matter

As it stands, intrusions into cryptocurrency exchanges require substantial resources at each phase—from initial reconnaissance and social engineering to elaborate credential harvesting and post-breach lateral movements. The introduction of advanced AI capabilities, even through models not specifically designed for this purpose, could greatly reduce the time and labor needed for successful attacks.

For instance, the FBI has attributed a staggering $1.5 billion theft to a cybercriminal entity known as TraderTraitor in early 2025, which executed a meticulously planned phishing attack over several months against a vulnerable Safe{Wallet} administrator. The level of effort involved demonstrates the labor-intensive nature of such cybercriminal enterprises.

North Korea's cyber actors don’t require artificial general intelligence (AGI) to improve their operations. What they need are tools that enhance the productivity of their operators. By investing in AI capabilities, any model offering analogous functionalities to what Mythos provides could significantly accelerate their operations, turning junior operators into effective players and compressing timeframes for planning and execution.

Identifying Access Patterns

There are three main types of access vulnerabilities that continue to intertwine in discussions about cybersecurity. Mislabeling or conflating these can undermine response strategies across the board.

1. Contractor Misuse: Legitimate employees of third-party vendors misusing their access is a known risk, as experienced in this recent Mythos breach. Effective defenses involve implementing strong behavioral monitoring and limiting access privileges.

2. Fraudulent Hiring Practices: Another tactic used by North Korean operatives involves embedding their agents in organizations under false pretenses. The Insikt Group's research has highlighted this trend, showing that adversaries use stolen identities to infiltrate companies, often within the tech sector. Strategies here should focus on identity verification at hiring and ongoing vetting processes.

3. Supply Chain Compromise: This technique refers to breaches of trusted vendors—an issue highlighted by incidents like the TeamPCP's LiteLLM compromise, which impacted an AI toolchain to reach final targets. The challenge lies in maintaining the integrity of build pipelines and ensuring rigorous artifact signing and monitoring.

These varying methods all converge on a single conclusion: limited-release AI models exposed to third-party environments face significant threats. North Korea stands out as a primary motivation, given their clear financial incentives tied to cyber heists.

The Bigger Picture

Within the security community, a mindset shift is necessary. Discussions around AI access must extend beyond traditional lab issues to include the ramifications of sanctions and geopolitical tensions. The notion of "controlled access" becomes increasingly questionable when facing a state-sponsored adversary motivated by a proven track record of monetizing cybercrime to support their operations.

What Lies Ahead

Instead of leaning on perimeter-style defenses that might falter against state-level threats, the emphasis should shift toward a framework that encompasses distinct infrastructure, near-real-time telemetry, and a rigorous vetting process tied to personnel rather than contractual documentation. Guessable endpoints must be the first priorities for elimination.

For crypto exchanges and custodians, it's essential to anticipate what capabilities entities like Lazarus will acquire in the coming months, rather than only focusing on past actions. An assumption that adversaries will improve faster than defense mechanisms is a prudent approach.

At the policy level, recognizing North Korea as a significant actor in the landscape of AI access governance is necessary. The existing sanctions frameworks have successfully documented cyber-enabled violations, yet they must evolve to specifically include AI capabilities as a relevant category for export control discussions.

For corporate Chief Information Security Officers (CISOs), understanding that third-party contractor vulnerabilities now reside firmly within the AI capability threat surface is vital, regardless of their previous comfort levels.

Final Thoughts

AI and Cybersecurity

The Mythos incident serves as a stark reminder of the cyclical vulnerabilities inherent in new AI deployments. Any entity whose operational model revolves around cybercrime will continue to exploit the weaknesses found at third-party seams. While this particular breach may have been perpetrated by hobbyists, the potential for exploitation by organized cybercriminal states remains a pressing concern that cannot be overstated.

Source: Thomas Davis · www.recordedfuture.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Lazarus Doesn't Need AGI