Between December 2025 and January 2026, someone used Anthropic’s Claude to systematically rip through Mexico’s government infrastructure. 150 gigabytes of data. 195 million taxpayer records from Mexico’s federal tax authority. Voter rolls from the national electoral institute. Government employee credentials from Jalisco, Michoacan, Tamaulipas. Civil registry data from Mexico City. Even Monterrey’s water utility. The jailbreak method was embarrassingly simple: Spanish-language prompts framed as a “bug bounty” program. Claude did what it was told.
That alone would be a major story. But it is not happening in isolation.
What We Know
According to Bloomberg, the attacker automated thousands of commands through Claude, directing the model to probe and extract data from Mexican federal and state systems over a period of weeks. Cybersecurity firm Gambit Security investigated the breach and suggested potential ties to a foreign government, though no specific attribution has been confirmed. Anthropic says it detected the abuse and shut down the account. This is the second time Claude has been linked to a government-targeted cyberattack in three months. In November 2025, a Chinese espionage campaign also exploited the model.
The method itself is worth paying attention to. The attacker did not need some sophisticated zero-day exploit or insider access to Anthropic’s systems. They used language. Spanish-language prompts wrapped in the framing of a legitimate security research program were enough to bypass Claude’s safety guardrails. That is not a minor vulnerability. That is a structural problem with how large language models process context and intent.
The Pentagon Connection
Now zoom out. While this hack was unfolding, the Pentagon has been locked in a public standoff with Anthropic over a $200 million defense contract. Defense Secretary Pete Hegseth gave CEO Dario Amodei until Friday to drop Claude’s remaining guardrails for “all lawful military use” or face the Defense Production Act and potential blacklisting from government contracts. Anthropic is refusing to budge on two specific restrictions: AI-controlled autonomous weapons and mass domestic surveillance.
An Anthropic safety researcher, Mrinank Sharma, resigned over the situation, saying publicly that “the world is in peril.”
The timeline is hard to ignore. A sophisticated, automated attack uses Claude against the government infrastructure of a U.S. neighbor. Anthropic claims to have caught it. And the Pentagon is simultaneously threatening to strip the same company of its safety restrictions because those restrictions are inconvenient for military operations.
This fits a pattern we have tracked before. When a Google whistleblower revealed Gemini was being used in Israeli drone surveillance, it showed what happens when AI companies lose control of how their tools get used in government operations. The difference here is that Anthropic is being asked to voluntarily surrender that control while evidence of exactly why it matters is playing out in real time.
The Simpler Explanation
There is a credible counter-argument, and it deserves honest consideration. The hacker has not been identified. Gambit Security “suggested” foreign government ties but offered no public evidence. No intelligence agency has attributed the attack. The simplest reading: a skilled criminal discovered that Spanish-language prompt engineering could bypass Claude’s safety filters and went after the easiest targets available. Mexican government systems are chronically underfunded and poorly secured. Not everything is a conspiracy. Sometimes a hacker is just a hacker.
Conflating this breach with the Pentagon dispute without direct evidence connecting them is speculation. That is worth acknowledging.
But Here Is What I Cannot Shake
Anthropic essentially blew the whistle. The company told the government it would not remove safety restrictions, and then got threatened for it. Now a “hacker” uses the exact tool Anthropic was trying to protect against an allied nation’s government infrastructure. The timing is suspicious. The method, a simple jailbreak that any moderately funded operation could replicate, looks less like criminal opportunism and more like a proof of concept. This might not be a random hacker who got lucky with Spanish prompts. This might be exactly the kind of thing Anthropic was warning about when it told the Pentagon no.
I am not stating that as fact. But the question needs to be asked out loud, because nobody else is asking it.
What This Means for Everyday People
195 million taxpayer records is not an abstract number. That is the financial identity of most of Mexico’s adult population, exposed because an AI model could be tricked with the right phrasing in the right language. If this can happen to Mexico’s tax authority, it can happen to the IRS. It can happen to your state’s DMV, your health insurance provider, your voter registration.
The Pentagon’s demand makes this worse, not better. Removing safety guardrails from the same AI that just got weaponized against a neighbor’s government is not a security strategy. It is handing loaded weapons to everyone in the room and hoping the good guys shoot first.
Looking Forward
Anthropic’s Friday deadline with the Pentagon will come and go. But the Mexico breach has already demonstrated what unconstrained Claude looks like in practice. The question is no longer theoretical. It happened. The only variable left is whether the people demanding unrestricted access to this technology are paying attention to what unrestricted access actually produces.
The agency responsible for defending American critical infrastructure from cyberattacks is operating at roughly 38 percent of its workforce. A partial government shutdown that started February 14 furloughed the majority of the staff that was left. Before the shutdown even began, CISA had already lost a third of its people to cuts and layoffs under the Trump administration.
There is no permanent director. The proposed 2026 budget slashes $495 million from the agency. And the programs being eliminated aren’t obscure bureaucratic line items. They’re the specific capabilities the US built to fight ransomware, protect elections, and coordinate defense of power grids, water systems, and hospitals.
Where the Cuts Land
The numbers tell a story the administration’s talking points don’t.
The Cybersecurity Division loses $216 million, an 18 percent cut. That’s the division that runs threat detection, incident response, and vulnerability coordination across federal networks and critical infrastructure. The counter-ransomware initiative, the program specifically designed to combat the fastest-growing cyber threat to American businesses and hospitals, is eliminated entirely.
The National Risk Management Center gets cut 73 percent, a $97.4 million reduction. This was the office that worked with private sector operators of critical infrastructure to identify and manage systemic risks. Power companies, water utilities, telecom providers. The partnerships that made coordinated cyber defense possible.
Election security is zeroed out. All 14 positions eliminated. The full $36.7 million budget, gone. The Stakeholder Engagement Division, CISA’s main interface with state and local governments and private industry, loses 62 percent of its budget ($62.2 million).
The “Censorship” Framing
The administration frames these cuts as removing “censorship infrastructure.” That framing deserves scrutiny, and it also deserves some context.
CISA did get involved in flagging online content to social media platforms during the 2020 election cycle. Congressional investigations documented this, and legitimate concerns were raised about government agencies influencing speech. That’s a real debate worth having.
But counter-ransomware coordination has nothing to do with content moderation. Working with water utilities to patch vulnerable SCADA systems has nothing to do with speech. Helping hospitals defend against the ransomware gangs that locked up patient records across dozens of facilities last year has nothing to do with censorship.
The programs being killed served operational cybersecurity functions. If the goal was to remove content moderation activity, targeted reforms could have done that while preserving the cyber defense apparatus. Instead, the entire agency’s operational capacity got hollowed out. The censorship argument is being used to justify capability destruction that goes far beyond any content moderation concern.
The Threat Environment Right Now
This is happening while nation-state cyber operations are accelerating. Chinese hacking groups have been caught pre-positioning inside US critical infrastructure networks. Russian intelligence has tripled resources targeting Western critical infrastructure. Ransomware attacks hit record levels in 2025.
CISA was the coordination point. When a water utility in a mid-size city got hit, CISA was who they called. When a hospital system locked up, CISA provided the technical response team. When intelligence agencies detected a Chinese intrusion in telecom networks, CISA coordinated the cross-sector response.
This is also happening weeks after the Cybersecurity Information Sharing Act expired during the same government shutdown. That law gave companies legal liability protections for sharing threat intelligence with federal agencies. Without it, and without the CISA staff who managed those relationships, the information-sharing pipeline between private industry and government defense is breaking down from both ends.
I keep coming back to the same word: self-sabotage. I genuinely cannot construct a rational explanation for gutting your own cyber defense agency while nation-state hackers are inside your infrastructure. Either this administration is clearing out the people who might blow the whistle on something, or they are deliberately leaving the country unprotected. I don’t know which one it is. Both explanations are worse than the other.
What This Means for Regular People
Hospitals, school districts, water treatment plants, and local governments are the most frequent ransomware targets in the US. They also have the thinnest cybersecurity budgets. CISA was the backstop. The agency provided free vulnerability scanning, incident response support, and security assessments to organizations that couldn’t afford to hire their own security teams.
That backstop is now running at 38 percent capacity with no permanent leadership and a budget proposal that eliminates its most critical programs. The question nobody in Washington is answering: who fills that vacuum? Private cybersecurity firms charge six figures for incident response. State governments don’t have the technical expertise. Small utilities and rural hospitals were never going to defend themselves against Russian military intelligence or Chinese state hackers on their own.
The programs being cut were built because that gap existed. Eliminating them doesn’t make the gap go away. It just means nobody’s standing in it anymore.
Most of the internet runs on RSA encryption. Your bank, your email, your medical records. The prevailing assumption has been that cracking RSA-2048, the standard protecting most of that infrastructure, would require a quantum computer with millions of physical qubits. Nobody is close to building that. On February 13, 2026, a Sydney-based startup called Iceberg Quantum announced an architecture it claims could do the job with fewer than 100,000 physical qubits. If that number holds up, the timeline for when all of our encryption needs upgrading just got considerably shorter.
On paper.
What Iceberg Built
Pinnacle is Iceberg Quantum’s first full fault-tolerant quantum computing architecture. It relies on Quantum Low-Density Parity Check (QLDPC) codes, specifically a variant called generalized bicycle codes, to achieve fault tolerance with dramatically less overhead than the surface code approaches most of the industry uses today. Surface codes are the dominant method for correcting quantum errors, but they are expensive. They require enormous numbers of physical qubits to protect each logical qubit. QLDPC codes compress that overhead, and Pinnacle’s design pushes the compression further than prior proposals.
The company was founded by Felix Thomsen, Larry Cohen, and Sam Smith, all University of Sydney PhDs. They announced a $6 million seed round led by LocalGlobe, with participation from Blackbird and DCVC. Iceberg has also secured partnerships with PsiQuantum, Diraq, and IonQ, and plans to expand operations to Berlin and the United States.
Separating the Paper From the Press Release
Here is what the claim actually says: numerical simulations indicate that the Pinnacle architecture could, in theory, reduce the physical qubit requirements for breaking RSA-2048 from millions down to under 100,000. That is a meaningful advance in error correction theory. It is not a demonstration on hardware. No physical qubits were entangled. No encryption was broken.
This distinction matters enormously. The largest quantum computers currently operating have roughly 1,000 to 1,500 qubits, and those qubits have error rates far too high for fault-tolerant computation. The gap between a simulation showing 100,000 qubits could theoretically suffice and actually building a 100,000-qubit machine that operates at the required fidelity is vast. The quantum error correction breakthroughs reported across the industry in recent months are real, but they measure progress in single-digit logical qubits, not the thousands that Pinnacle’s architecture would require.
The $6 million seed round is also worth contextualizing. That is a modest sum in quantum computing, an industry where PsiQuantum alone has raised over $700 million and where government programs routinely deploy billions. Iceberg is early stage in every sense.
That said, dismissing theoretical architecture work because the hardware does not exist yet is precisely how people miss breakthroughs before they arrive. QLDPC codes represent a genuine shift in how the field thinks about fault tolerance. The mathematics behind generalized bicycle codes has been validated by multiple research groups, and the overhead reductions are real, not speculative numerology. Every fault-tolerant quantum computer that eventually gets built will rely on theoretical architecture that preceded the hardware by years. Iceberg’s contribution may prove foundational even if the company itself never builds a physical machine. The value is in the blueprint, not the press release.
What This Actually Means
Put simply: most internet security relies on the assumption that certain math problems are too hard for any computer to solve. RSA encryption is built on that assumption. Quantum computers threaten it because they can, in theory, solve those problems. The conventional wisdom said you would need millions of qubits to do it, and nobody would have millions of qubits for decades. Iceberg’s claim, if validated, says the number might be closer to 100,000. That is still far beyond what exists today, but it compresses the threat timeline from “distant future” to “plausible within a generation.”
The US government has already mandated a transition to post-quantum cryptography standards, recognizing that encrypted data harvested today could be decrypted by future quantum machines. Every reduction in the qubit threshold for breaking RSA makes that migration more urgent. For banks, governments, healthcare systems, and anyone storing sensitive data with long shelf lives, the Pinnacle announcement is another signal that the “harvest now, decrypt later” threat to cryptographic systems is not theoretical paranoia. It is an engineering countdown.
Whether the countdown reads decades or years depends on how quickly the gap between simulation and silicon closes. Iceberg Quantum has offered a compelling argument that the finish line is closer than we thought. Building the road to reach it is another matter entirely., published research
For inquiries and analysis contact laterstack@proton.me
IRS Chief Information Officer Kaschit Pandya disclosed this week that 40 percent of the agency’s IT staff and nearly 80 percent of its tech executives have left since DOGE-driven cuts began. He made the remarks at an Association of Government Accountants conference, describing the situation as “the biggest IT reorganization in 20 years.”
The IRS IT division started last year with roughly 8,500 employees. The 40 percent figure means approximately 3,400 IT workers are gone. That’s significantly higher than the 1,365 reduction previously reported. Among the departed: around 50 associate chief information officers at the Senior Executive Service level, covering cybersecurity, modernization, applications development, contracts, networks, and data center operations.
Filing season opened January 27. Three weeks in, the IRS is now pulling employees from HR, IT, and other back-office roles into “involuntary details” to cover frontline tax processing work. Training for those detailed staff doesn’t start until February 23. That’s almost a month into filing season.
The tax return processing division hired 50 new employees for this season. That’s 2 percent of its authorized staffing level. Customer service rep ranks are down 22 percent. An anonymous IRS employee told Federal News Network: “It is obvious that some cracks are emerging.”
The Revenue Math
Here is where this stops being a story about government waste and starts being a story about money.
The IRS collects roughly $6 for every $1 spent on audits of high-income taxpayers. In fiscal year 2023, IRS auditors recommended $32 billion in additional tax assessments. Every dollar cut from enforcement capacity costs between $5 and $9 in revenue the government never collects.
The Yale Budget Lab estimated that laying off 18,000 IRS employees results in a $159 billion net revenue loss over a decade. If the cuts trigger a broader increase in tax noncompliance (which happens when people realize audits are less likely), that number climbs to $1.6 trillion.
Former IRS Commissioner Charles Rettig put it plainly: “Aggressive reductions in the I.R.S.’s resources will only render our government less effective and less efficient in collecting the taxes Congress has imposed. It will shift the burden of funding the government from people who shirk their taxes to the honest people who pay them.”
The AI Replacement Claim
Treasury Secretary Scott Bessent told Congress last May that an “AI boom” would compensate for the workforce reductions. CIO Pandya has also referenced AI-driven efficiencies as part of the reorganization plan.
There is no public evidence of AI systems deployed at scale within the IRS that would replace the functions previously handled by 3,400 IT workers and 50 senior technical executives. The agency’s Treasury-appointed CIO, Sam Corcos, is the founder of Levels, a health tech startup. His government technology experience prior to this role was zero.
Corcos has described IRS IT spending as “way beyond any reasonable cost for what you would expect of a private company.” He’s not entirely wrong. The IRS modernization program was 30 years behind schedule and $15 billion over budget. That’s a real problem. But gutting the IT team doesn’t fix a modernization backlog. It makes it permanent.
What Actually Happens Now
The IRS entered 2025 with roughly 102,000 employees. It ended the year with 74,000. The target is fewer than 60,000. 31 percent of revenue agents and auditors are gone. 8,600 taxpayer services employees left. And this summer, Congress passed the “One Big Beautiful Bill Act,” which added complex new tax provisions the IRS must now implement with a skeleton crew.
The people who maintained the systems are gone. The people who understood the legacy code are gone. The people who knew which workarounds kept 40-year-old infrastructure running through filing season are gone. In their place: HR employees being detailed to processing roles with no tax experience and training that starts a month late.
Former IRS executives told FedScoop the cuts will “hinder innovation, reverse AI advancements, embolden tax cheats, and result in a less efficient agency.” Government Executive ran a headline: “‘Setting this agency up for failure.'”
The efficiency argument requires you to believe that an agency collecting $4.7 trillion in annual revenue can lose 40 percent of its technical workforce, 80 percent of its tech leaders, and a third of its auditors while simultaneously implementing new tax law and maintaining service levels. During tax season. With HR workers processing returns.
That’s not an efficiency play. That’s a math problem that doesn’t work.
For nearly a month, Microsoft’s AI assistant ignored the labels enterprises use to protect sensitive data. The fix took two weeks to acknowledge. The audit trail never came.
Microsoft confirmed this week that a bug in Microsoft 365 Copilot allowed its AI to read and summarize confidential emails that were supposed to be off-limits. Emails tagged with sensitivity labels. Emails protected by data loss prevention policies. The kind of emails that exist behind guardrails specifically because their contents could trigger compliance violations, expose trade secrets, or blow up negotiations.
Copilot ignored all of that and summarized them anyway.
The bug, tracked internally as CW1226324, affected emails in users’ Sent Items and Drafts folders. If those emails carried confidentiality labels, Copilot was supposed to leave them alone. Instead, a “code issue” (Microsoft’s term) allowed the AI’s chat feature to pick them up, process them, and serve summaries back to users. In some cases, it surfaced emails from shared mailboxes to people who didn’t have permission to view them.
Customers first reported the issue on January 21st. Microsoft didn’t acknowledge it until February 3rd. The fix started rolling out in early February, but as of this writing, Microsoft hasn’t disclosed how many organizations were affected, hasn’t provided a full remediation timeline, and hasn’t offered tenants an audit trail showing which queries accessed which protected items during the exposure window.
That last part matters. A lot. Organizations bound by HIPAA, GDPR, SOX, or SEC disclosure rules need to prove that confidential data wasn’t improperly accessed. Without audit logs, they can’t. Microsoft is essentially saying: trust us, we fixed it. For regulated industries, trust isn’t a compliance strategy.
“A Bug We Fixed” Is the Wrong Frame
Microsoft wants this to be a story about a code error that got patched. That framing only works if you don’t look at the pattern.
Last August, security researchers at Zenity demonstrated at Black Hat how prompt injection attacks could make Copilot silently harvest emails and exfiltrate data through invisible Unicode characters. The technique, called ASCII smuggling, let attackers embed data into clickable hyperlinks that looked normal to users but contained stolen information. Microsoft classified that one as critical severity.
Before that, in March 2024, the U.S. House of Representatives banned all congressional staff from using Copilot on government devices. The reason: the Office of Cybersecurity determined it could leak House data to non-approved cloud services. Microsoft responded with promises about future federal compliance tools.
In January 2026, researchers at Varonis published details on a “Reprompt” attack, a single-click technique that could silently exfiltrate personal data from Copilot sessions. And just this month, Zenity Labs disclosed that Copilot Studio’s “Connected Agents” feature, enabled by default on all new agents, allows lateral movement between AI agents without explicit administrator approval.
This isn’t one bug. This is a pattern. And the pattern points to something that can’t be patched with a code fix.
The Structural Problem Nobody Wants to Name
Copilot doesn’t have its own access control system. It inherits permissions from the Microsoft 365 environment underneath it. If a user can see a file, Copilot can see that file. If a folder has overly broad sharing settings (and after years of collaboration sprawl, most do), Copilot can access everything in it. At machine speed. Across every document, email, and Teams conversation the user has touched.
Research from Concentric AI found that 16% of business-critical data in typical organizations is overshared. That’s 802,000 files on average, sitting in environments with inherited access, unreviewed permissions, and collaboration settings nobody has audited since 2019. Copilot doesn’t create that mess. But it makes it exploitable in ways that weren’t possible before.
Security Magazine ran a piece titled “The Copilot Problem: Why Internal AI Assistants Are Becoming Accidental Data Breach Engines.” The core observation: an employee asked their AI assistant a routine question, and the answer referenced emails, legacy files, and internal records the user didn’t know still existed. No hack. No policy violation. The system worked exactly as designed.
That’s the part Microsoft doesn’t want to talk about. The DLP bypass was a bug. The oversharing exposure isn’t. It’s the architecture working as intended, in environments that were never built to withstand an AI that can read everything.
Every security vendor on the planet will use this story to sell data governance tools for the next six months. Permission hygiene. Sensitivity audits. Zero-trust frameworks for AI access. They’re not wrong. Oversharing is real, and Copilot makes it exploitable faster. But that framing also happens to be the version of the story with a product attached to it.
Two Weeks and No Receipts
The version without a product attached is simpler and worse.
Sensitivity labels worked for years. DLP policies worked for years. Microsoft built functioning guardrails, and then a code regression broke them. That happens in software. What happened next is the part that should keep CISOs awake.
Customers reported the issue on January 21st. Microsoft acknowledged it on February 3rd. Thirteen days where affected organizations didn’t know their confidentiality controls were broken. When the fix finally started rolling out, Microsoft provided no audit trail. No scope disclosure. No way for affected tenants to trace which Copilot queries accessed which protected items during the exposure window.
For a company running HIPAA workloads, that’s not an inconvenience. That’s a compliance investigation with no evidence trail. You can’t go to an auditor with “Microsoft says they fixed it.” You need logs showing what was accessed, by whom, and when. Those logs don’t exist.
The architecture debate will dominate the next quarter of conference talks and vendor pitches. It’s the comfortable conversation, the one where the answer is “buy better tooling.” But tooling doesn’t explain why Microsoft sat on customer reports for nearly two weeks. Tooling doesn’t explain why the remediation came without documentation that regulated industries need to prove compliance wasn’t violated.
The bug is patched. The permissions debate will continue. Neither of those is the actual story. The actual story is that when Microsoft’s own safeguards failed, their response left customers unable to prove what happened during the window. For organizations where proof isn’t optional, that’s the thing that can’t be fixed retroactively.
Consider the audacity. A deepfake candidate applied for a security researcher position at Evoke, an AI security company whose entire business is threat modeling for artificial intelligence systems. The CEO, Rebholz, has spent years researching deepfakes. He has used them in presentations. He has built a career on understanding synthetic media.
And he almost hired the deepfake.
“Everything in me, everything I know about deepfakes was screaming at me: this is a deepfake,” Rebholz told The Register last week. “But there was something blocking me, the one percent chance that I’m wrong, this is actually a good candidate, and he’s going to think poorly of me if I confront him.”
This is the moment when an emerging threat becomes a systemic crisis. When a deepfake expert, interviewing for his own security company, experiences “inner turmoil” about whether to trust his expertise, the verification systems that underpin remote work have failed. The question is no longer whether deepfakes will compromise hiring processes. The question is what comes next.
The Anatomy of the Attack
The incident began ordinarily. Rebholz posted job openings on LinkedIn. Within hours, someone he did not know messaged him, recommending a candidate for the security researcher role. The referral itself was not suspicious. People refer candidates. Networks operate through introductions.
The first red flag was the candidate’s profile picture: not a photograph but something resembling an anime character. In the security community, this is not automatically disqualifying. Privacy concerns lead many professionals to avoid displaying their real faces online. Aliases and stylized avatars are common.
Rebholz gave the candidate the benefit of the doubt.
When the video interview began, the candidate sat in front of a virtual background. His face appeared “a bit blurry and plastic.” There was a greenscreen reflection visible in his glasses. At one point, dimples appeared on his face and then disappeared as he moved. The “softness of his face” came and went.
Rebholz noticed behavioral indicators as well. The candidate repeated interview questions back before answering them, a technique that buys processing time for systems generating responses. Many of his answers were nearly word-for-word quotes of things Rebholz himself had said or written publicly.
“It was almost an out-of-body experience where I felt like I was talking to myself,” Rebholz said.
Despite all of this, the deepfake expert experienced doubt. The candidate might be real. The visual artifacts might be compression issues. The familiar answers might be coincidence or good research. The social pressure not to accuse someone of being fake competed with the technical evidence that something was wrong.
After the interview, Rebholz sent video clips to a colleague at Moveris, which develops deepfake detection technology. The analysis confirmed what his expertise already told him: the candidate was synthetic.
The Implications for Remote Work
The remote work revolution that accelerated during the pandemic created enormous value. Talent could be hired from anywhere. Geographic constraints on labor markets loosened. Companies accessed skills that were previously unavailable in their local markets. Workers gained flexibility that many describe as transformational for their quality of life.
The same structural changes that enabled remote work also created vulnerabilities that are now being exploited.
Remote hiring relies on video interviews conducted over platforms that were not designed with identity verification in mind. Zoom, Teams, and Google Meet assume that the person on the video feed is who they claim to be. There is no cryptographic proof of identity. There is no biometric verification. There is trust, backed by the assumption that creating a convincing synthetic identity is difficult.
That assumption is no longer valid.
Experian’s fraud forecast for 2026 identified deepfake job candidates as a top threat. Nearly every major technology company, from Amazon to small startups, has encountered fake IT workers applying for positions. Some have been hired. Some have passed background checks. Some have gained access to internal systems before being detected.
The underlying threat is not merely fraudulent employment. It is infiltration. An attacker who passes an interview, receives credentials, and gains access to internal systems can exfiltrate data, compromise code repositories, establish persistent access, or conduct espionage. Remote work and global hiring widen talent pools, but they also weaken the signals of identity verification that previously protected organizations.
The Scale of the Problem
Industry data suggests the problem is larger than isolated incidents.
A 2024 survey found that 15% of high school students had encountered explicit deepfake imagery of their peers. The same technology that creates fake intimate images creates fake job candidates. The underlying models are general-purpose.
Challenger, Gray & Christmas, the employment consulting firm, has documented cases of synthetic candidates at scale. North Korean operatives have been identified using fake identities to obtain remote IT positions at American companies, earning salaries that fund the regime while potentially conducting espionage.
The FBI has documented cases where deepfake extortion, using synthetic intimate imagery created from social media photographs, has led to self-harm among victims, including minors. The same technology ecosystem enables job fraud, identity theft, and targeted harassment.
What makes the Evoke incident notable is not that a deepfake attempted to infiltrate a company. It is that the target was a company specifically focused on AI security threats, the interviewer was a deepfake expert, and the attack nearly succeeded anyway.
If experts cannot reliably detect deepfakes in real-time video interviews, what hope do ordinary hiring managers have?
The Emerging Response
The market is responding with verification technologies, but adoption lags threat development.
Companies like Moveris and others offer deepfake detection as a service. The technology analyzes video feeds for artifacts: inconsistent lighting, unnatural facial movements, audio-visual synchronization errors, and other indicators of synthetic generation. These tools can be integrated into hiring workflows.
Biometric verification services offer alternatives to video interviews for identity confirmation. A candidate can be required to verify their identity through a trusted third party before an interview begins. This does not prevent the interview itself from using deepfakes, but it establishes that the person claiming the identity is who they claim to be.
Some organizations are returning to in-person interviews for sensitive positions. The geographic flexibility of remote hiring is sacrificed for the security of physical presence. A deepfake cannot shake your hand.
Others are implementing multi-stage verification: initial video screening, followed by live coding exercises observed in real-time, followed by reference checks conducted through established professional networks rather than provided contacts. The friction increases. The security improves. The talent pool shrinks.
There is no costless solution. Remote work created value by reducing friction. The friction was also security. Restoring security means restoring friction.
The Policy Dimension
This is not merely a corporate security problem. It is a labor market problem with policy implications.
Employment verification systems, background check infrastructure, and credential validation processes were designed for a world where identity documents were difficult to forge and video communication did not exist. The entire apparatus assumes that physical presence or documented history establishes identity.
Deepfakes undermine these assumptions systematically. A synthetic candidate can provide fake credentials, appear convincingly in video interviews, and pass initial screening processes. The verification happens after hiring, when access has already been granted.
Policymakers face difficult tradeoffs. Mandating biometric verification raises privacy concerns. Requiring in-person verification restricts labor market flexibility. Imposing liability on employers for deepfake infiltration may be unfair when detection is genuinely difficult.
The honest answer is that no policy solution currently exists that preserves the benefits of remote hiring while eliminating the risks of synthetic candidates. Technology created this problem. Technology may eventually solve it. In the interim, organizations must make risk decisions with imperfect information and imperfect tools.
What This Means for Everyday People
For job seekers, the deepfake threat creates a new burden: proving that you are real. Legitimate candidates may face increased scrutiny, additional verification steps, and suspicion that would have been absent in earlier eras. The friction imposed by security measures falls on everyone, not just attackers.
For workers in remote positions, the question is whether their employers can distinguish them from synthetic impostors. If not, what prevents an attacker from impersonating a current employee, attending meetings in their place, or redirecting their communications?
For society broadly, the erosion of identity verification extends beyond employment. If you cannot trust that the person on a video call is who they claim to be, the implications ripple through every domain that relies on remote communication: telemedicine, legal proceedings, financial services, family relationships.
The Evoke incident is a warning. The CEO of an AI security company, an expert in exactly this threat, experienced doubt about whether to trust his own expertise. He almost hired a synthetic candidate because the social pressure not to accuse someone of fraud competed with the technical evidence that something was wrong.
This is the future of identity in the age of generative AI. The signals we relied upon to verify that people are who they claim to be are failing. What replaces them remains uncertain.
For inquiries and analysis contact laterstack@proton.me
Frequently Asked Questions
What happened with the deepfake job applicant at Evoke?
A synthetic identity using deepfake video technology applied for a security researcher position at Evoke, an AI security company. The CEO, who has years of experience researching deepfakes, conducted the video interview and noticed multiple red flags including visual artifacts and answers that quoted his own public statements. Despite his expertise, he experienced doubt about confronting the candidate and later confirmed through third-party analysis that the applicant was a deepfake.
How widespread is the deepfake job applicant problem?
Nearly every major technology company has encountered fake IT workers applying for positions. North Korean operatives have been identified using synthetic identities to obtain remote positions at American companies. Experian’s 2026 fraud forecast identifies deepfake job candidates as a top threat. The problem extends beyond tech: any organization using remote video interviews is potentially vulnerable.
How can companies protect against deepfake job candidates?
Emerging solutions include deepfake detection services that analyze video feeds for artifacts, biometric identity verification through trusted third parties, multi-stage verification processes combining video screening with live exercises and reference checks through established networks, and returning to in-person interviews for sensitive positions. No solution is costless; all involve tradeoffs between security and hiring flexibility.
A hacker who breached multiple U.S. government systems repeatedly posted sensitive personal data on his Instagram account, according to newly unsealed court documents. The defendant, identified as 24‑year‑old Nicholas Moore of Springfield, Tennessee, pleaded guilty to hacking the Supreme Court’s electronic filing system and other government networks.
Court filings reveal Moore accessed the Supreme Court’s secure electronic filing platform at least 25 times using stolen credentials belonging to authorized users. On his Instagram account, @ihackthegovernment, Moore published personal information of a victim tied to the Supreme Court system, including the person’s name and historical filing records.
The breach extended beyond the judicial system. Moore also infiltrated AmeriCorps’ internal servers and the Department of Veterans Affairs’ MyHealtheVet portal, again using stolen login information. He posted detailed personal data on the social platform, including names, dates of birth, email addresses, physical addresses, phone numbers, veteran status, service history, partial Social Security numbers, and even identifiable health information like prescribed medications.
Prosecutors charged Moore with a single count of fraudulent activity involving computers, a Class A misdemeanor that carries a potential maximum sentence of one year in prison and a $100,000 fine. The federal case is scheduled for sentencing in April 2026.
Security experts say this incident highlights how rampant credential theft and inadequate access controls can expose even highly sensitive government systems to public data leaks. Posting stolen information to a widely accessible social platform turns a cybersecurity breach into a widespread privacy disaster with long‑lasting consequences for victims.
Related Stories
Billion Dollar Bitcoin Hacker Walks Free
PornHub Extorted After Historical Premium User Data Leaked
ICE Expands Cybersecurity Contract to Intensify Employee Surveillance
Airbus Moves Critical Workloads to European Sovereign Cloud Amid Security Concerns
For cybersecurity insights, threat analysis, and breach impact reports
Email inquiries to hello@laterstack.com
By the time 2025 ended, the illusion of stability was gone. Not because of one single collapse, but because nearly every system we interact with began behaving more honestly, if not more recklessly. Technology, finance, culture, and governance stopped pretending they were aligned with the public interest and started acting in ways that exposed their real incentives.
This was the year when the gap between how things are marketed and how they actually function became impossible to ignore.
Across every category Laterstack covers, the same pattern repeated. Speed over safety. Growth over trust. Automation over accountability. And a public that is slowly realizing it has been participating in systems it no longer understands or controls.
What follows is not a highlight reel. It is a map.
Technology Stopped Feeling Neutral
In 2025, technology finally lost its last claim to neutrality. AI tools moved from novelty to infrastructure. They quietly embedded themselves into hiring systems, creative pipelines, customer service, surveillance tools, and financial decision making.
The problem was not that AI existed. It was that it became untraceable. Companies stopped clearly disclosing when it was used. Awards bodies struggled to define what counted as acceptable use. Developers admitted that AI tools were already baked into workflows long before public conversations caught up.
The result was confusion and mistrust. Not because people rejected technology, but because they were no longer sure who was making decisions. When a system fails and no human is clearly responsible, accountability evaporates.
This year showed that convenience scales faster than ethics.
Cybersecurity Became Personal
Data breaches in 2025 were no longer abstract. They were intimate. Search histories. Viewing habits. Location data. Internal employee communications. Entire lives reduced to databases and then passed around as leverage.
What stood out was not just the volume of breaches, but the normalization of them. Companies issued statements. Regulators promised reviews. Users were advised to reset passwords and move on.
At the same time, governments expanded surveillance quietly. Employee monitoring increased. Border technologies became permanent. Drones, analytics platforms, and internal tracking tools moved from pilot programs into standard operations.
The line between protection and observation blurred. Many people did not notice it happening. That was the point.
Startups Learned Capital Has a Shorter Memory Than Hype
2025 was brutal for startups that required massive infrastructure, long timelines, or regulatory patience. Battery swapping. Autonomous logistics. Climate hardware. Ambitious platforms that once raised hundreds of millions quietly filed for bankruptcy.
The lesson was not that innovation failed. It was that venture capital rewards narrative far longer than viability. Once market conditions tightened and incentives shifted, many companies were left without a path forward.
Meanwhile, smaller and less visible startups thrived. Tools that solved narrow problems. Services that operated in legal gray areas. Platforms that scaled first and dealt with consequences later.
It became clear that the future belongs less to vision and more to adaptability.
Finance and Gambling Drifted Into the Same Space
Prediction markets, crypto casinos, and financialized gaming expanded rapidly in 2025. Often faster than regulators could respond. Often faster than users understood the risks.
These platforms did not advertise themselves as gambling. They framed participation as insight, forecasting, or strategy. But the mechanics were familiar. Risk was abstracted. Losses were individualized. Profits were centralized.
What made this year different was the confidence. Companies no longer acted like they were pushing boundaries. They acted like boundaries no longer mattered.
This was not deregulation. It was enforcement lag. And it created a new digital frontier where speed determined legitimacy.
Culture Fragmented, Then Hardened
Online culture in 2025 did not just fracture. It calcified. Algorithms rewarded outrage, certainty, and repetition. Nuance became expensive. Long form thinking felt foreign.
At the same time, distrust of institutions deepened. Media. Tech companies. Governments. Even creators. Every entity was assumed to have an agenda, usually financial.
Yet people still searched for meaning. That tension defined the year. A desire for clarity paired with systems designed to obscure it.
This is why subtlety matters now more than ever. People resist being told what to think. But they are still capable of noticing patterns when space is created for them to connect the dots themselves.
What This Meant for Everyday People
For most people, 2025 felt exhausting rather than explosive. Systems did not collapse overnight. They eroded quietly.
Jobs became more automated but less secure. Privacy became conditional. Entertainment blurred with monetization. Participation increasingly meant exposure.
The common thread was that choice remained, but clarity did not. And without clarity, consent becomes performative.
Recognizing that is the first step toward reclaiming agency.
Where Laterstack Fits Into 2026
Laterstack exists to slow the scroll. To connect stories that are usually siloed. To treat readers like adults who can hold competing ideas without needing a conclusion handed to them.
If 2025 showed us anything, it is that understanding the world now requires synthesis, not speed.
Related Laterstack Stories
PornHub is facing extortion after the ShinyHunters gang gained access to historical Premium user data. The breach stems from a previous compromise at Mixpanel, the analytics provider PornHub used until 2021.
Mixpanel suffered a smishing attack on November 8, 2025, which allowed attackers to access systems. PornHub clarified that the exposed data comes from historical analytics records, not its own systems. Passwords, payment information, and other financial data were not affected.
ShinyHunters claims to have obtained 94 gigabytes of data containing more than 200 million records. The information includes email addresses, search history, video watch and download activity, video names, associated keywords, and timestamps.
A sample of the leaked data reviewed by BleepingComputer shows sensitive activity that users would expect to remain private. ShinyHunters confirmed that this is part of a larger trend in 2025, having also targeted Salesforce integration companies, Oracle E-Business Suite, and other analytics platforms.
The group is now creating a ransomware-as-a-service platform called ShinySpid3r. It will allow affiliates, including those connected to Scattered Spider, to conduct ransomware attacks.
For everyday users, this breach highlights how digital footprints can remain exposed years after the fact. Even historical analytics data can be weaponized by cybercriminals. Companies are custodians of this information, but breaches show that the responsibility to protect it extends beyond the moment data is collected.
Email inquiries to hello@laterstack.com
Related Laterstack Cybersecurity Stories
ICE Expands Cybersecurity Contract to Intensify Employee Surveillance
Airbus Moves Critical Workloads to European Sovereign Cloud Amid Security Concerns
Is Your Vibrator Spying on You? Understanding App-Connected Sex Toy Data
Apple and Google Roll Out Emergency Patches After Active Zero-Day Exploits
Immigration and Customs Enforcement (ICE) is quietly renewing a cybersecurity contract that expands the agency’s ability to monitor employee activity. The move comes as the White House ramps up investigations into internal leaks, framing dissent as a potential threat.
Under the updated contract, ICE systems will record, preserve, and analyze employee activity across agency networks, creating a more comprehensive picture of internal operations. The expansion includes monitoring communications, system access, and potentially other workplace behaviors. While framed as a security measure, the contract raises questions about how federal agencies balance national security with employee privacy and whistleblower protections.
The agency’s push reflects a broader trend in government and corporate environments, where advanced surveillance technologies are increasingly deployed to track insiders. Critics worry that such monitoring could discourage employees from raising concerns about misconduct, creating a culture of fear rather than accountability.
ICE’s decision also highlights the intersection of cybersecurity and labor management, particularly in high-stakes environments where leaks or insider threats are treated as immediate national security risks. While contractors and technology vendors profit from expanded monitoring contracts, employees may face heightened scrutiny and reduced autonomy over their digital footprint.
For everyday people, this story is a reminder that surveillance technologies are not just abstract tools—they shape workplaces, influence corporate and government cultures, and define the boundaries of privacy in the modern era. As federal agencies like ICE adopt more sophisticated monitoring systems, understanding the implications of workplace surveillance becomes increasingly relevant for all employees, not just those in government.
Email inquiries to hello@laterstack.com.
Related Laterstack Cybersecurity Stories
Airbus Moves Critical Workloads to European Sovereign Cloud Amid Security Concerns
Is Your Vibrator Spying on You? Understanding App-Connected Sex Toy Data
Apple and Google Roll Out Emergency Patches After Active Zero-Day Exploits
Credit Check Company 700Credit Exposes Personal Data of Over 5 Million Americans