WeeklyWorker

01.10.2026
FBI badge and Glock 22 service pistol

Hacking in a fragile world

As the FBI has found to its cost, from state actors to trivial script-kiddies, hackers are on the attack. The networked world is more vulnerable than ever. But why? asks Paul Demarty

Tough times at the Federal Bureau of Investigation, whose hiring website has apparently been compromised.

Such is the claim of ShinyHunters - a criminal hacking group, who assure readers that they have acquired by this means personal data on all FBI agents ever recruited through this portal. That would be quite a grim prospect, given the FBI’s extensive use of undercover tactics to achieve its core aims of suppressing dissent, and entrapping young men into planning terrorist plots for the agency to heroically ‘foil’. ShinyHunters promises to release all this material if the FBI does not take down an unflattering description of the group as essentially trivial ransomware script-kiddies with delusions of grandeur. It seems to have really stung …

This fiasco is largely being attributed, in the press, to the incompetence of FBI director Kash Patel. On one level, this is quite understandable: Patel, after all, really is incompetent, even by the generous standards of the second Trump administration. A second-tier Epstein-conspiracy podcaster by background, we can only assume that he was given the role so the FBI could be used for Trump’s programme of revenge-lawfare; but the effect of putting this cracked cretin in charge has been mostly to paralyse the agency altogether and give Trump’s enemies an ‘all you can eat’ buffet of chucklesome gaffes to feast on.

The early stages of several high-profile investigations, then, have been bungled, notably the assassinations of Brian Thompson and Charlie Kirk, and the kidnapping of Nancy Guthrie, the elderly mother of an NBC News host, now presumed dead. Patel’s extensive travel on FBI expenses has attracted criticism, and a long, recent article in the Atlantic alleges, based on extensive anonymous sources, that he is essentially an alcoholic (he is suing them). At the beginning of this year, Iranian hackers compromised his personal email account and now there is this fresh hack. It rather fits the pattern.

Negligence

Yet there are other patterns here. Cybersecurity has been in the news a lot lately, particularly in relation to strange goings on at the AI frontier labs, OpenAI and Anthropic. There was the recent Hugging Face incident, where an internal security research experiment at OpenAI resulted in a days-long hack of the Hugging Face model-hosting service by thousands of AI agents. Then, last week, Australian prime minister Anthony Albanese revealed that another rogue OpenAI agent had hacked the Australian healthcare system and accessed secret files. This took place months ago, but OpenAI did not report it to the Australian authorities until much later.

It is not only by the negligence of OpenAI and Anthropic, as they desperately cast around for a path to profitability that will allow them to go public in good order, that AI is implicated in all this. The one absolutely cast-iron productivity improvement the large language models (LLMs) have made in real-world work is to programming, which after all maps well to the LLM as a function - the input is a text description of the required software, and the output is, once more, text, in the form of a computer program. Programming languages, moreover, are highly structured and include tools for verification; and, thanks to the success of the open-source movement, there is an enormous corpus to train on.

The trouble is that a hack, at the end of the day, is just a program like any other. It interacts with the same wider systems as legitimate software; it is composed of the same stuff and runs on the same hardware. Thus the very same coding agents I and my colleagues in the industry use every day are, irreducibly, also expert tools for unauthorised intrusions. It seems barely a week goes by, these days, without some catastrophic hacking incident being reported. Government departments and large private enterprises alike suffer from these attacks.

Who are the attackers? Criminal gangs like ShinyHunters, of course, but also nation-state actors. In the west, Russia catches a lot of flak for this sort of activity, and mysteriously Israel does not; but both are hard at it, as are, we must assume, all other significant world powers. The impact of AI here is a downward-levelling one. Of course, the US and Israel have access to better tech than Russia or Iran; but you do not actually need to be on the latest and greatest stuff to make a lot of mischief.

We are already, I think, in the diminishing-returns phase of the frontier research, so far as code-generation is concerned, which is one of the many economic headwinds faced by the frontier labs. The ‘rogue agent’ problems at OpenAI seem to be an excrescence of an attempt to find a new product, specifically for cybersecurity, that people can be charged a lot of money for. A few rough edges still need to be sanded off before they can take this to market, at the very least.

But the problem may be more fundamental. To repeat: hacking is just programming (plus a bit of social manipulation - phishing and the like). The frontier models come with guardrails to prevent malicious use, for sure; but the evidence is that there are ways to get around them. Anthropic’s Dario Amodei, in his call for coordinated slowdown, himself noted that Anthropic’s flagship system, Claude, had been used for targeting by the Houthis during their recent military advance. It was also implicated in bombing the girls’ school in Iran early in the current war, and no doubt many other atrocities of that sort.

In any case, how does one harden a system against intrusion? One very important method is: by trying to hack it, and if you succeed, fixing the vulnerabilities discovered. This is a perfectly legitimate use for AI coding that is completely indistinguishable from malicious use, except by context that the systems lack (whether I am a contractor carrying out a penetration test, for instance). Then there is the ‘rogue agent’ problem, which is that you must disable the safeguards to do anything useful in such a test, and the system may then go on to do something … surprising.

Thus one description of the AI coding boom might be: an incomprehensibly vast, accidental penetration test of the entire internet, and by extension all economic and state activity somehow connected to the internet. The results of this test are, to put it mildly, not reassuring. Every corner cut to meet a release date, every piece of deferred maintenance, every slightly out-of-date version of an ‘open-source software library’ on every server - all subjected to the attention of this unblinking eye of Sauron.

Competition

To return to the theme of a recent article of mine,1 so much discussion of the dangers of AI is unhelpful, because it is filtered through the boutique science-fictional obsessions of industry participants, whose idea of the threat is more or less that superintelligent, self-directing software systems are just around the corner and poised to take over: the Terminator scenario.

Instead of indulging these fantasies, we should look at what is in front of our eyes. Have we ‘lost control’ of AI? Perhaps that is one way of putting it: but the reality is that we do not have control and never have had it, because we have a capitalist market and competition between capitalist states, which together pose insoluble coordination problems.

Even without these problems, fixing all this would be difficult. In the most extreme cases, with powerful state-actors backing attacks, total resilience is simply unachievable. Recall the Stuxnet attack on Iranian nuclear centrifuges, in which a bespoke malware targeted at the specific control systems in use was delivered, on a USB flash drive by a spy, to the centrifuge - very wisely not on any accessible network! So long as such adversaries exist, we will just have to take our chances, if we are not to give up on computers altogether - which we certainly cannot, if we hope to fill eight billion bellies reliably.

That said, I offer some qualified hope. It is my experience in the software industry - and I think this is true of relevant parts of the hardware industry too - that engineering professionals typically want to do a better job than they are permitted. We certainly do not want to get woken up in the middle of the night by news of a ransomware attack, and we have enough expertise to significantly reduce the vulnerability of our creations to such attacks if we are given the time and space to do so.

There is, admittedly, only so much time in the day; but the obstacles to better practice in this area stem ultimately from the fact that the software industry is astonishingly and inexcusably wasteful in its current form. It is dominated - why would it not be? - by capitalist managers, whose objective is to maximise shareholder value or, in the private venture-capital-backed scene, to game a series of financial and usage metrics to attract further investment.

To illustrate the problem: Marks & Spencer suffered a serious attack not long ago. The vulnerable operations were outsourced to a lowest-bidder body-shop. After all, corporate IT management is not ‘core’ to M&S’s business activities, which consist basically of logistics and marketing. Vast amounts of engineering time is spent - any reasonable person would say wasted - on automating the marketing, so they can grab a few more quid out from under Sainsbury’s or H&M. This problem simply does not exist without the capitalist market, just as Stuxnet-type attacks could not exist without antagonistic competition between states.

So, tempting as it is, we cannot lay the blame for the FBI’s current difficulties at the feet of the weapons-grade moron Kash Patel. That is, in a sense, to give him too much credit, as if an FBI director of sufficient intelligence and professionalism could anticipate all possible cyber-attack vectors. The problem is more radical: criminality and sabotage of this sort is just what happens when you give capitalism a computer.


  1. ‘Angel or McGuffin?’ Weekly Worker September 17: weeklyworker.co.uk/worker/1601/angel-or-mcguffin.↩︎