Stolen Secrets, Autonomous Hackers, and 153 Million Stolen Identities
How this was made Verified AI
Every Intellegix briefing is generated from that day's broadcast and run through automated checks before it publishes — with a human paged on any flag. Here is the trail for this edition.
A former Google engineer was sentenced this week for stealing AI trade secrets — specifically, proprietary information about Google's AI chip designs and large language model architectures representing billions of dollars in research and development. The case was prosecuted under the Economic Espionage Act, which covers trade secrets stolen for the benefit of a foreign government or company. Prosecutors have been increasingly aggressive about applying the statute to AI technology, and the sentence was intended to create real deterrence for engineers who might be approached — systematically — by foreign intelligence services or companies operating as fronts.
Defense contractor Booz Allen Hamilton — which pulls in roughly $11 billion in annual revenue — announced the development of an AI model capable of autonomously hacking networks without human assistance. The claim warrants critical scrutiny. There is a meaningful difference between an AI that automates known exploit scripts against known vulnerability classes and one that independently discovers novel vulnerabilities, develops custom exploits, and executes multi-stage intrusions against hardened targets. The first category is useful but not a qualitative leap beyond what sophisticated security teams have done with scripted tools for years; the second would represent something genuinely new. Booz Allen's system, based on available information, appears closer to the first category described in language that implies the second — a pattern common to defense contractor capability announcements that serve contract renewal and budget justification purposes as much as accuracy.
The FBI is investigating a dark web listing of more than 153 million driver's license scans. If the database is as comprehensive as advertised, it contains biometric-quality identity data — photos, signatures, addresses, dates of birth, and machine-readable information used for identity verification across dozens of commercial services — on the majority of American adults. Synthetic identity fraud, already the fastest-growing category of financial crime in the United States, becomes substantially easier with high-quality document scans. Unlike credit card numbers, the compromised credentials here cannot be changed: there is no mechanism for victims to obtain a new face or date of birth. By the time any charges are filed, the data will already have been distributed across numerous downstream buyers. The realistic response at this stage is hardening the verification systems that rely on this data rather than recovering the data itself.