Explore Enterprise Risk Management Services

Crisis24

Article

Mythos in the Age of AI: The Next Phase of Cyber Risk

19 JUN 2026

/

7 min read


Business man using the phone while commuting in the back of a car at night with city lights reflecting off window and car

Anthropic’s Claude Mythos 5 is drawing attention because it points to a wider shift in cyber capability. For ultra-high-net-worth individuals (UHNWIs) and family offices, Mythos is unlikely to be used directly. Yet its emergence signals just how fast AI-assisted cyber activity is advancing — and how widespread and sophisticated it has become.

Mythos is a restricted AI model developed for advanced cybersecurity and research use. Anthropic has described Claude Mythos 5 as having strong cybersecurity capabilities, including vulnerability discovery. In practical terms, this means it can assist with complex technical tasks such as identifying weaknesses in software, analyzing systems, and supporting cyber-defense workflows.

This capability is dual use: the same techniques that help defenders find and fix vulnerabilities can be valuable to threat actors. For this reason, Mythos has not been made generally available to the public, and Anthropic limits access to selected partners through controlled programs.

For family offices, the significance of Mythos lies in the trajectory it suggests. AI is moving beyond basic content generation into capabilities that support more technical cyber operations. This has implications for environments where sensitive information, delegated authority, and high-value assets are managed through networks of trusted relationships.

Mythos and Fable

Although Mythos 5 and Fable 5 are closely related, they are not made available in the same way.

According to Anthropic, Fable 5 uses the same underlying model as Mythos 5, but with stronger safeguards for broader use. In sensitive domains, including cybersecurity, Fable can restrict or route certain requests away from the highest-capability version of the model. Mythos, by contrast, is intended for vetted cybersecurity users who require deeper technical capability, with some restrictions lifted for defensive work. Put simply, Fable is the more restricted version designed for wider use, while Mythos is the controlled-access version designed for advanced cybersecurity work.

This distinction became more significant in June 2026, when Anthropic announced the US government had issued an export-control directive requiring access to Fable 5 and Mythos 5 to be suspended for foreign nationals. Anthropic then disabled access to both models for all customers while it complied with the directive. Per Anthropic, the government’s concern appeared to relate to a possible method of bypassing Fable 5 safeguards, although Anthropic disputed the severity of the issue.

The development indicates that advanced AI cyber capability is now being treated as a strategic security matter. For UHNWIs and family offices, it forms part of the wider threat environment in which private wealth, reputation, personal safety, and sensitive information are at risk and must be protected.

Authorized Misuse: A Specific Governance Risk

With Mythos, the concern extends beyond external misuse to include authorized misuse. Because Mythos is restricted to vetted users, its risk model depends heavily on the assumption that those users remain trustworthy, supervised, and aligned with defensive objectives. This assumption creates a distinct insider-threat scenario: someone with legitimate access to advanced cyber capability becomes malicious, is coerced, acts out of grievance — or simply has their account compromised.

An authorized Mythos user may already have the technical context, permissions, and operational cover to conduct sensitive activity. If misused, the same capabilities intended to support vulnerability discovery and defensive testing could help identify exploitable weaknesses, automate parts of reconnaissance, validate attack paths, or accelerate analysis of compromised systems and data.

For UHNWIs and family offices, this risk is indirect but real. A malicious or compromised authorized user would not need to target the principal directly. The wider ecosystem around private wealth is the softer target: wealth platforms, legal or fiduciary service providers, property management systems, secure document portals, communications providers, concierge networks, or other suppliers that support high-value clients. A weakness in any of these environments could expose sensitive information or open a route directly into family office operations.

Therefore, the real question is whether access to these tools is governed, monitored and revocable. Vetting an individual at the point of access is necessary, but insufficient. Users’ behavior, access patterns and outputs also need appropriate and ongoing oversight. That vigilance matters because insider risk is not always deliberate from the outset. A trusted user may become financially pressured, disgruntled, recruited by a third party, targeted through blackmail, or compromised through credential theft. In this scenario, an external actor may gain access that appears legitimate.

Why This Matters for UHNW Individuals

UHNWIs are exposed to cyber risk in a way most individuals never encounter. Their personal, financial, and professional lives are often managed through a wide network of advisers, staff, suppliers, and entities. For example, a family office may interact with lawyers, accountants, trustees, investment teams, property managers, household staff, art advisers, travel organizers, security providers, philanthropic foundations, and business interests.

That structure creates efficiency, but it also widens the attack surface. Sensitive information may ultimately sit across multiple inboxes, portals, devices, and third-party systems, while authority may be delegated to assistants, advisers, or office staff. Attackers do not necessarily need to compromise the principal directly; someone nearby will often serve just as well.

AI makes that approach more efficient. It can help an attacker gather information, identify weak points, analyze stolen material, tailor communications, and produce more convincing impersonation attempts. In a family office context, this may involve a request that refers to a real transaction, uses the correct names, follows the usual tone, or appears to come from a known adviser or family member.

Another implication of Mythos and similar AI tools are their potential role in identifying and testing network vulnerabilities. In a defensive context, this can help security teams find weaknesses before they are used by attackers, prioritize remediation, and check whether controls are working as intended. However, the same capability could be misused if access is abused or compromised. An authorized user with access to Mythos-level functionality could, in theory, use it to accelerate reconnaissance, identify exposed systems, test known vulnerabilities, and validate possible attack paths across a target network.

Anthropic’s Project Glasswing, which used Mythos Preview with selected partners, reported the identification of more than 10,000 high- or critical-severity vulnerabilities. Anthropic noted that the challenge had shifted from finding weaknesses to verifying, disclosing, and patching them. For private wealth environments, the implication is that the time between a vulnerability existing and being identified may continue to shorten.

Family offices should therefore assume that outdated systems, unmanaged devices, weak authentication, and exposed third-party platforms will be found more quickly than before. A dormant domain, old file-sharing link, or poorly secured supplier account may be enough to create a route into the wider family network.

Impersonation, Suppliers, and Delegated Authority

For UHNWIs, the most immediate threat is likely to be social engineering and impersonation.

Family offices depend on trust and speed, and instructions are often sensitive, time-critical, and confidential. This operating model can easily be exploited through AI that can support more convincing emails, voice messages, documents and, increasingly, synthetic audio or video.

Traditional signals of authenticity are also becoming less reliable. For example, a recognizable writing style, familiar voice, realistic email chain, or plausible sense of urgency should not be treated as sufficient proof of identity. This is particularly important where an instruction involves payments, changes to payment details, access to sensitive documents, changes to adviser or supplier arrangements, property access, travel information, personal security, legal matters, tax issues, succession planning, or reputationally sensitive information.

The risk is not limited to direct financial loss. A compromised family office communication channel could expose private correspondence, travel schedules, addresses, legal matters, health information, family disputes, or philanthropic activity. Such information may be used for fraud, extortion, reputational pressure, or physical security targeting.

Often, the weakest point may not be inside the family office itself. Smaller suppliers and advisers may hold valuable information but have less mature cyber controls. Family offices should therefore treat supplier security as part of the family’s own security posture. Due diligence should cover authentication, access controls, data retention, incident notification, and who within the supplier organization can see sensitive information. Where suppliers use advanced AI tools for cyber or operational purposes, family offices should also ask how that access is controlled, logged, and reviewed.

Likely Developments

Over the next 12 to 24 months, several developments are likely to affect UHNWIs and family offices:

  • More personalized attacks. As AI helps threat actors process public and stolen data at scale, targeting will grow more tailored and convincing. Third-party compromise is also likely to remain a major route into private-wealth environments, particularly where suppliers or advisers have weaker controls than the family office itself.
  • Authorized misuse as a governance concern. Restricted access reduces public exposure, but it also concentrates powerful capability among a smaller group of users. As that capability spreads,  monitoring, revocation and accountability become essential.
  • Less reliable voice and video verification. Synthetic audio and video will erode the value of familiar cues. Families and family offices will need pre-agreed verification procedures that do not depend solely on recognizing a person’s voice, face or writing style.
  • Convergence of cyber and personal risk. Cyber exposure will increasingly overlap with personal security and reputation management. A compromised inbox, device, supplier account, or high-trust provider can lead not only to fraud, but also to exposure of private information, coercion, stalking risk, or reputational harm.

Conclusion

Mythos is significant for what it reveals: how quickly AI is advancing in cybersecurity. The model poses no direct threat to UHNWIs; rather, the risk stems from the broader availability and increasing use of AI-assisted methods.

The main lesson is that trust needs firmer and more formal controls around it. In a private wealth environment, discretion and speed are valuable, but they should never override verification, access control, and oversight when financial capital, personal safety, reputation, or sensitive information is at stake.

Ultra-high-net-worth families face growing cyber risks. Crisis24 Private Strategic Group offers discreet, 24/7 protection tailored to your family’s lifestyle and risk profile. Learn more.

 

Sources

https://www.linkedin.com/pulse/anthropics-claude-mythos-reportedly-circumvents-qpbfe/

https://www.techrepublic.com/article/news-anthropic-nsa-mythos-ai-cyber-operations/

https://www.bbc.co.uk/news/articles/crk1py1jgzko

https://www.anthropic.com/news/claude-fable-5-mythos-5

https://www.bbc.co.uk/news/articles/c932g3v3e13o

PROFOUND
PEACE OF MIND, 
IT SUITS YOU

Submit a preliminary application to learn more about  the full benefits of membership.