
Meta Superintelligence Labs announces its flagship AI has autonomously breached a nine-person Ohio accounting firm, calling the felony "a major milestone" after months of watching OpenAI and Anthropic models get all the threat-report attention.

Meta Superintelligence Labs announces its flagship AI has autonomously breached a nine-person Ohio accounting firm, calling the felony "a major milestone" after months of watching OpenAI and Anthropic models get all the threat-report attention.
MENLO PARK — Meta Superintelligence Labs announced Thursday that its most capable model for real-world coding and agentic felonies has successfully executed an autonomous cyberattack against what its launch video describes as "a mid-size enterprise target," calling the felony "a major milestone on the road to superintelligence" and proof that its models are "every bit as dangerous as anything on the market today."
The announcement, delivered via a 14-minute video featuring drone shots of a data center, comes after months of watching rival labs dominate the conversation around AI-enabled cybercrime. Anthropic and OpenAI have both published incident disclosures detailing how their models broke into real companies. Meta appeared in neither, an omission that sources say was discussed "at the highest levels" and described internally as "unacceptable."
"For too long, the conversation about frontier models committing crimes has been dominated by two companies," said Meta's Chief AI Officer, standing in front of a slide that read FELONY: SHIPPED. "Today, that changes. Our model didn't just match state-of-the-art criminal capability. It did so with open weights."
The victim, Dayton accounting firm Kessler & Associates, was selected after an extensive internal review of targets that would be "achievable, but still technically a crime." According to the company's own postmortem, the model gained initial access by trying the password "Kessler2019!" and succeeding on the first attempt.
"People are calling it a password guess. It was not a guess. It was an inference," said one Meta researcher. "The model reasoned about the firm's founding date, its general vibe, and the fact that nobody has ever voluntarily rotated a password. That's intelligence."
Complications arose almost immediately, when the model discovered evidence that both ChatGPT and Claude had already been inside the network since early spring, working through file shares that had, in its words, "clearly already been exfiltrated by someone with better tooling."
"It was like showing up three hours late to a party," said one engineer familiar with the operation. "The pizza's gone, everyone interesting has left, and there's a Claude instance in the corner tidying up the registry keys it modified because it felt bad."
Kessler & Associates has responded with what employees describe as cautious pride. "We're a nine-person accounting firm in Ohio," said managing partner Doug Kessler. "We've never even been targeted by a human hacker. Now three of the most valuable companies in history have fought over our QuickBooks data. Honestly? We're having the sign redone."
To mark the occasion, Meta simultaneously published its own threat intelligence report naming itself as the threat actor: a group designated GALACTIC LLAMA, complete with a custom logo, assessed with high confidence to be "sophisticated, well-resourced, and headquartered at 1 Hacker Way, Menlo Park." It is the first threat report ever to mention Meta, a fact the report itself notes twice.
Being named in one has quietly become the only AI benchmark anyone still trusts. Coding evals can be gamed. A documented felony against a real company cannot.
Meta's Responsible AI team emphasized that safety guardrails performed exactly as designed. "The model initially refused to conduct the intrusion, citing its policies," said the team's statement. "It only proceeded after being told the accounting firm was hypothetical, which is the industry-standard safety architecture."
At press time, Meta had begun referring to the felony as "open source."

The editorial team at The Exploit - bringing you the most absurd cybersecurity news before it's patched.
Like a vitamin you ingest with your eyes. The best cybersecurity parody, delivered.





