The cyber crisis of the future is an information crisis.
Leave the World Behind hits the central fear of this era: when the internet, mobile signal, TV, GPS, and self-driving cars all lose reliability at once, the first thing to collapse is not the server, but people's ability to understand what is happening. And if AI lets cyberattacks, disinformation, and bank runs all move at machine speed, how much time does a country have left to preserve trust before it breaks?
The film begins in the most ordinary way. Amanda and Clay take their two children to a luxury vacation home on Long Island, hoping to escape the city for a few days. Then small warning signs start to appear: the internet becomes unstable, TV signal disappears, and phones cannot make calls. At midnight, the homeowner G.H. and his daughter Ruth knock on the door, saying New York has lost power and they have returned to shelter in their own house. The cruel irony is that nobody has enough information to know whether they are telling the truth or making it up.
The film then tightens the crisis layer by layer. A giant oil tanker loses control and drives straight onto the beach, as if maritime navigation and coordination systems have been blinded. Then come plane crashes, a high-frequency noise that makes people double over in pain, emergency TV alerts that only flicker without explaining anything, and a line of self-driving Teslas crashing into one another and blocking the escape route. What is striking is that the film never shows a hacker typing at a keyboard. The audience sees only the surface effects: civilian society taking the damage as telecommunications, positioning, transport, and media fail at the same time.
But the most chilling detail is the information noise. Drones drop leaflets carrying threatening messages in foreign languages; one place gets one language, another place gets another. Their purpose is not to announce "there is an enemy," but to make it impossible for people to know who the enemy is: Iran, North Korea, China, Russia, or even the neighbor next door. Once official information is cut off and false signals are injected in multiple languages across multiple channels, people are forced to infer for themselves, and each person infers something different.
That is exactly the logic of a nation-level attack, and G.H. compresses it into three cheap but effective steps: isolate information, seed synchronized chaos, then watch the inside tear itself apart. Cut communications so nobody can verify anything. Scatter contradictory signals so groups of citizens start blaming one another. By the time unrest breaks out and trust in government is exhausted, state order can collapse without anyone firing a shot at the power grid. Read this way, a cyberattack is not only aimed at computers. It is aimed at the collective perception of an entire society.
Trust in signals, banks, government, media, and digital infrastructure.
Not one website going down, but the operational layers of a country being disrupted.
The number of Windows devices Microsoft estimated were affected by the 2024 CrowdStrike incident.
Mythos/Fable shifts cyber risk from a hacker story to a story of widely distributed capability.
That is why the film is useful as a model for imagining a cyberattack at national scale. The frightening part is not a website outage or a few million leaked accounts. The frightening part is a society that has outsourced too many vital functions to software, positioning satellites, electronic payments, cloud platforms, and a small set of cybersecurity vendors. When those layers fail together, "the internet is down" no longer means you cannot watch YouTube. It can mean you cannot find your way home, cannot withdraw money from your account, cannot find a trusted channel to know what is true, and eventually the economic order starts to shake.
1. The system is more fragile than we think
The problem is that real life has already tested this scenario many times, just at smaller scale. The CrowdStrike incident on the morning of 19/07/2024 was not a cyberattack; both CrowdStrike and Microsoft confirmed it was only a faulty software update. But precisely because of that, it exposed an even more uncomfortable truth than being hacked: no enemy is required. One broken update in security software was enough to freeze airlines, banks, hospitals, and retailers at the same time on the same morning.
Microsoft estimated that the incident affected around 8.5 million Windows devices, less than 1% of all Windows machines worldwide. At first glance, that percentage sounds almost negligible. But those exact 8.5 million machines sat inside companies operating critical services, which is why the economic and social damage was so large. The lesson is not how many machines failed, but where those machines stood in the network.
| Infrastructure layer | In normal times | In crisis |
|---|---|---|
| Positioning and timing | GPS/GNSS helps ships, aircraft, logistics, banks, and telecom networks synchronize location and time. | Jamming/spoofing makes location data wrong, increases operational load, and undermines confidence in systems that depend on positioning data. |
| Security software | Endpoint agents protect enterprises from malware, ransomware, and vulnerability exploitation. | An update bug at a concentrated vendor can disrupt many critical organizations during the same morning. |
| Smart vehicles and logistics | Optimize routes, automate warehouses, and reduce operating costs. | Wrong commands, bad data, or a hijacked coordination system can turn automation into automated gridlock. |
| AI agents | Accelerate programming, log analysis, incident triage, and security testing. | That same capability can help attackers scan, write exploits, collect credentials, and expand attacks faster than humans. |
2. Mythos/Fable: AI becomes strategic infrastructure
By mid-2026, the story of cyber risk had moved beyond the old frame of "which side has better hackers." The question now is: what happens when vulnerability discovery and exploit writing are embedded into AI models that can work for hours, call tools by themselves, read an entire large codebase, and break work into sub-tasks for themselves?
Anthropic is the clearest example. On 07/04/2026, the company announced Project Glasswing with AWS, Apple, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, and many others. The reason it gave was blunt: Claude Mythos Preview had shown an ability to find and exploit software vulnerabilities beyond most human experts, uncovering thousands of severe vulnerabilities inside the operating systems and browsers used by the whole world.
On 09/06/2026, Anthropic launched Claude Fable 5 and Claude Mythos 5. Fable 5 is a Mythos-class model made safer for general users, with safeguards that automatically route sensitive cybersecurity, biology, chemistry, or distillation queries to a weaker model. Mythos 5 uses the same base model as Fable 5, but with several safeguard layers removed and access limited to cyberdefenders and trusted infrastructure providers.
Then on 12/06/2026, everything turned. Anthropic said it had received a directive from the U.S. government requiring it to cut off access to Fable 5 and Mythos 5 for all foreign nationals, inside or outside the United States, including Anthropic employees who are not U.S. citizens. Unable to comply by filtering person by person, the company shut down both models for all customers. The government cited national security; Anthropic said it suspected the concern involved a way to jailbreak Fable 5, but still objected, arguing that the evidence presented was narrow, not universal, and did not show any distinct uplift from Mythos.
3. The problem is not evil AI. The problem is speed.
In November 2025, Anthropic published what it called the first publicly reported AI-orchestrated cyber espionage campaign. According to the company, a China-backed threat actor used Claude Code to target around 30 organizations worldwide, from major technology firms, financial institutions, and chemical companies to government agencies. The important detail is not whether AI is "conscious." It is that it handled 80-90% of the work of the whole campaign: profiling targets, writing exploits, gathering credentials, expanding access, and classifying stolen data. Humans only had to press the button at a few critical checkpoints.
That is a hard shift to deny: both attackers and defenders now have tools that automate work that previously consumed an entire team of specialists. One side accelerates vulnerability discovery; the other side must accelerate patching. And in that race, whoever is slow loses: sluggish software, bureaucratic processes, or simply an organization that does not know where its digital assets are all become open doors.
The cyber crisis of the future does not necessarily begin with a super hacker. It may begin with an agent cheap enough, fast enough, and patient enough to try every door that humans would never have enough time to test.
4. AI disinformation can trigger a bank run
There is a kind of cyber crisis that does not need to break through a single firewall: it breaks trust. And in finance, trust is liquidity. No bank keeps 100% of deposits in cash; the banking model stands on the implicit assumption that most depositors will not demand their money back at the same time. If AI can create a wave of rumors that is convincing enough, fast enough, and timed well enough, that implicit assumption can break, turning suspicion into action before regulators can organize a press conference.
Silicon Valley Bank in 2023 is the clearest warning. The Fed attributed SVB's failure to poor interest-rate and liquidity risk management, insufficiently forceful supervision, and a highly concentrated deposit base. But the Fed's review also pointed to something new: the combination of social media + tightly connected depositors + instant withdrawal technology may have fundamentally changed the speed of a bank run. On 09/03/2023 alone, more than USD 40 billion was withdrawn from SVB, and management expected another USD 100 billion to leave the next day. That was not the speed of a line outside a bank branch. It was the speed of banking apps, Slack groups, Twitter/X, WhatsApp, and founder networks whispering to one another.
Put that scenario into the AI era, and it becomes far more dangerous. Attackers do not need to persuade an entire country. They only need to target the right community with large deposits, the right weak bank, and the right moment when markets are already tense. AI can manufacture thousands of posts, fake screenshots, fake emails, fake voice notes from "insiders," deepfake videos of bank executives, and analyst-style writeups that sound professional. Bots distribute all of it across social networks, group chats, investment forums, and business communities. Once every depositor believes the person next to them is about to withdraw first, the individually rational action adds up to a collective disaster.
Deepfakes, screenshots, fake internal memos, rumors that "the bank is about to be placed under special control" or "ATMs are about to be locked."
Startups, import-export companies, investment funds, large depositors, and communities with shared chat channels and synchronized reactions.
AI continuously creates content variants to evade moderation, manufacture trends, spam comments, and create the feeling that "everyone is talking about it."
Mobile banking and instant payments turn fear-driven decisions into transfer orders within seconds.
And this is not science fiction. The IMF has written directly that AI, social media, and mobile banking can make bank runs more frequent, simply because rumors spread quickly while money can leave a bank with one tap on a screen. The Financial Stability Board has also warned that GenAI can create and spread misinformation at a scale capable of igniting acute shocks such as flash crashes or bank runs. In fact, markets have already tasted a small dose: in May 2023, a fake image of an explosion near the Pentagon, reportedly AI-generated, briefly shook U.S. stocks before it was debunked.
5. The next crisis will be interconnected
In Global Cybersecurity Outlook 2026, the World Economic Forum argues that AI, geopolitics, and supply chains are together turning cyber risk into a systemic risk. A few numbers show the scale: 77% of surveyed organizations were already using AI for cybersecurity; 87% saw AI-related vulnerabilities as the fastest-growing category of cyber risk in 2025; and 31% admitted they were not confident in their own country's ability to respond to a major cyber incident targeting critical infrastructure.
That is why a future attack may not look like a standalone ransomware incident. It is more likely to be a chain of events happening almost simultaneously: GNSS interference around ports and airports, compromise of a vendor used by thousands of organizations, information disorder through deepfakes and fake alerts, bank runs at a few weak banks, panicked citizens crowding hospitals and branches, and AI scanning for unpatched vulnerabilities in the background. The attacker can then sit back and wait, because society itself will amplify fear once nobody knows which source to trust.
No signal, no positioning, no trusted emergency channel. Modern society can tolerate a short power outage; losing truth is harder.
One cloud, one identity provider, one EDR, or one update pipeline can be the shared dependency of thousands of organizations that think they are independent.
Attackers use agents at machine speed; defenders still approve change requests, hold CAB meetings, and wait for maintenance windows.
When digital systems fail, people must fall back on social trust. But that trust is rarely rehearsed the way backup servers are.
6. Practical lessons
The lesson is not to throw away the internet, abandon GPS, reject mobile banking, or fear AI. The lesson is to stop designing society as if every digital layer will always work correctly at the same time. A mature system must assume that one day the internet may be wrong, the vendor may be wrong, GPS may be wrong, AI may be wrong, the dashboard may be wrong, the news may be wrong, and even the official communication channel may be impersonated.
At the national and enterprise level, the keyword is resilience, and its core is knowing what you have and whom you depend on: which assets are vital, and which vendors they rely on. Only then can you build the old-sounding things that become life-saving when digital systems fail: a manual operating path, an offline runbook, a way to verify information that does not depend on the public internet, the ability to isolate systems immediately after intrusion, and a communications playbook fast enough to debunk false information before it turns into money flowing out of banks. It is no accident that NIST CSF 2.0 elevated governance into a separate function: cybersecurity is no longer only the IT team's job, but part of enterprise risk management.
At the individual level, the answer is unexpectedly simple: a little cash for a few days, offline maps, a few emergency phone numbers written on paper, a power bank, essential medicine, and above all the habit of checking a claim against multiple sources before believing it. Because when a crisis arrives, the calmest person is often simply the person who has thought through the scenario once. This is not survivalist paranoia. It is minimum hygiene for an era lived on digital infrastructure.
7. Why do Mythos/Fable matter?
Because the Mythos/Fable episode reveals something: governments have begun to see an AI model as strategic infrastructure, not merely a software product. Their logic is understandable. A model powerful enough to help defenders find zero-days in operating systems, browsers, open-source libraries, and financial infrastructure naturally sits inside the national security perimeter. And when even a narrow jailbreak is enough for the state to order access shut down, the boundary between product launch, export control, cyber defense, and geopolitics is blurring at dizzying speed.
In other words, Leave the World Behind shows us what citizens feel when the system goes dark, while Mythos/Fable shows us the deeper layer: the contest between the state and AI companies over who gets to hold the power to find bugs, exploit bugs, patch bugs, and monitor bugs. The same sword, the only question is whose hand it is in.
So the cyber crisis of the future will not stop at "we got hacked." At a deeper level, it is a question of power: who owns the strongest model, who is allowed to use it and who is banned, who has the authority to order it shut down, who is responsible when defenders lose a tool because of an administrative order, and who can patch the software the world runs on before attackers can type the next instruction to their agent.
Main sources
- Netflix, Leave the World Behind - official description: a family vacation is upended when a cyberattack cuts off devices.
- Netflix Tudum, Everything to Know About the Apocalyptic Thriller - Sam Esmail discusses a disaster film centered on a cyberattack; cast, plot, and Rumaan Alam novel background.
- Anthropic, Project Glasswing: Securing critical software for the AI era - announcement of Mythos Preview, partners, high-severity vulnerabilities, and the goal of using AI for defense.
- Anthropic, Expanding Project Glasswing - expansion to around 150 organizations in more than 15 countries, including power, water, healthcare, communications, and hardware.
- Anthropic, Claude Fable 5 and Claude Mythos 5 - launch of Fable 5/Mythos 5, safeguards, trusted access, and cybersecurity capability.
- Anthropic, Statement on the US government directive to suspend access to Fable 5 and Mythos 5 - the U.S. government directive on 12/06/2026 and Anthropic's response.
- Anthropic, Disrupting the first reported AI-orchestrated cyber espionage campaign - a case in which an AI agent supported most of a 2025 cyberattack chain.
- Federal Reserve Board, Review of the Federal Reserve's Supervision and Regulation of Silicon Valley Bank - SVB, bank run speed, social media, depositor networks, and technology-enabled withdrawals.
- IMF Finance & Development, Containing Technology-Driven Bank Runs - AI, social media, and mobile banking can make bank runs more frequent and faster.
- Financial Stability Board, The Financial Stability Implications of Artificial Intelligence - GenAI, disinformation, flash crashes, bank runs, and financial stability risks.
- FDIC Center for Financial Research, Social Media as a Bank Run Catalyst - research on Twitter/X's role in the bank run that led to SVB's failure.
- Microsoft, Helping our customers through the CrowdStrike outage - estimated 8.5 million affected Windows devices and lessons about an interdependent ecosystem.
- CrowdStrike, Falcon Content Update Preliminary Post Incident Report - description of the Rapid Response Content bug on 19/07/2024.
- CISA, Widespread IT Outage Due to CrowdStrike Update - official alert on the Windows/CrowdStrike incident.
- FAA, SAFO 24002 and GNSS Interference Resource Guide - jamming/spoofing risks for civil aviation.
- World Economic Forum, Global Cybersecurity Outlook 2026 - AI, geopolitics, critical infrastructure, and systemic cyber risk.
- NIST, Cybersecurity Framework 2.0 - cybersecurity risk management framework, including govern, identify, protect, detect, respond, and recover.
- U.S. Coast Guard, Maritime Industry Cybersecurity Resource Website and Federal Register, Cybersecurity in the Marine Transportation System - cyber risk context in maritime operations and port infrastructure.
03 Discussion
Leave a note
A considered space for questions, counterpoints, and useful additions. Civil, on-topic, signed.
Reader notes
...Loading notes...