When AI Meets Scale: The 15-Million-Person Day
We've reached a moment in infosec history where the scale of compromise and the speed of weaponization have synchronized in ways that should reshape how we think about defense.
In the past 72 hours alone, Charter Communications has reported 4.9 million compromised accounts and Carnival Corporation confirmed nearly 6 million victims—both claimed by the same extortion gang, ShinyHunters. That's 15 million people's personal information in the hands of attackers, much of it harvested months ago and only now surfacing on leak sites. These aren't isolated incidents. They're the visible tip of a compromise strategy that operates on a timeline that has nothing to do with our incident response playbooks.
What makes this week different from last week isn't just the volume—it's the velocity with which attackers are turning exploits into operational weapons. Consider the convergence: Threat actors are actively exploiting a critical FortiClient EMS vulnerability that Fortinet patched in April, deploying an undocumented credential stealer called EKZ within weeks. Simultaneously, a zero-day RCE in Gogs is allowing authenticated users to execute arbitrary code, and a vulnerability in Gitea has exposed 30,000 deployments to attacks that could pull private container images, source code, and credentials. These aren't hypothetical risks—they're exploitation-in-progress scenarios playing out across thousands of organizations.
But here's what's accelerating the timeline: AI is now part of the attack stack. GreyVibe, a Russia-linked threat group, is weaponizing ChatGPT and Gemini to generate social engineering lures and scale their campaign across military, government, and corporate sectors. Anthropic's planned rollout of Claude Mythos-class models to the public was delayed due to security risks—a quiet reminder that the same tools we're building for productivity are being reverse-engineered for exploitation. The industry is rightfully obsessing over agentic AI risks, but the real problem is that organizations don't know how to deploy these tools safely. When enterprise AI risk is heavily concentrated among a small group of "power users", you have a supply-chain vulnerability baked into the application layer.
Meanwhile, nation-state activity continues its steady evolution. Kimsuky has expanded its toolkit with HTTPSpy, HelloDoor, and VS Code Tunnel exploits to target South Korean military and corporate entities. And the malware-as-a-service market is maturing: BTMOB, an Android RAT, now operates with a builder interface that lets cybercriminals generate custom phishing payloads, spreading across Brazil and Latin America through a subscription model. JINX-0164 is targeting cryptocurrency firms with fake recruiter lures and macOS malware, a reminder that supply-chain attacks work because they exploit human judgment, not just code.
The infrastructure layer tells another story. We discovered this week that a Dutch police raid seized 800 servers from THE.Hosting but left the core IP space intact—meaning the hosting provider is already back in business. The operational technology surface is widening: medical devices from Fourth Frontier, physical access systems from ABB, and industrial converters from Jinan USR are all shipping with critical vulnerabilities. Building automation, medical telemetry, and industrial networking—the systems we depend on to run safely—are being exposed faster than vendors can issue advisories.
Yet here's the paradox that nobody seems to want to talk about: Nordic CISOs report they're facing no more serious cyberattacks than they did two years ago. The threat landscape has exponentially expanded—AI weaponization, zero-day exploits in active use, nation-state toolkit evolution, malware-as-a-service maturation—and yet some of the most sophisticated security programs in the world say the severity isn't increasing. That's either a sign of extraordinarily effective defense, or a sign that we've stopped noticing.
The disclosure debate is heating up too. Microsoft is pushing back against public zero-day drops, advocating for coordinated vulnerability disclosure, while the security research community is rightfully frustrated with the pace of vendor response. The tension is real, but the message from this week's events is clear: the race between exploit and patch has become the primary theater.
What gives us hope is the emerging category of AI-native security tools. Geordie just raised $30 million for AI security governance, and Edamame is building a runtime verification platform to catch AI coding agents going off the rails. These aren't defensive reactions—they're structural responses to the fact that the attack surface has fundamentally changed. We're building for speed, for agentic workflows, for enterprise-scale AI deployment, and the security tools need to operate at that velocity.
What we need to watch: whether organizations can patch at the speed exploits are being weaponized. FortiClient, Gogs, Gitea—these aren't theoretical vulnerabilities anymore. They're operational. The law enforcement wins matter (the 35-year-old arrested for hacking Ajax, the sextortionist sentenced to 33 years), but they're measured in years while the attack cycle is measured in weeks. The inflection point we're at isn't whether AI will change security—it's whether defenders can evolve faster than attackers can weaponize.
Key Takeaways
- ShinyHunters' 15-million-person haul in 72 hours shows that mega-breaches are now routine: When two of the world's largest corporations lose millions of customer records to the same gang months apart, the issue isn't the breach—it's the timeline mismatch between compromise and disclosure.
- Zero-day exploitation is accelerating: FortiClient, Gogs, and Gitea vulnerabilities are moving from patch Tuesday to active exploitation within weeks, driven partly by AI-assisted social engineering and automated payload generation.
- AI is both the multiplier and the solution: GreyVibe is weaponizing ChatGPT for lures while Geordie and Edamame are raising capital to build AI-native defenses—the industry is in an arms race that will define the next five years.
- Patch velocity is now your primary security metric: It doesn't matter how good your detection is if threat actors can weaponize open-source vulnerabilities across 30,000 deployments before most organizations even know they're exposed.
The Wire is HackWire's daily editorial briefing, published every morning.