Bharat Threat FeedGlobal threats, decoded for Indian defenders
AI Threat Watch · 4 August 2026

AI Threat Watch — 4 August 2026

Four disclosures this week trace back to a boundary that looked intact but was not actually verified: a testing environment assumed to be isolated, a package name assumed clean because it looked machine-generated, a breach-cost curve that now has AI stamped on more than a quarter of its entries, and a familiar face on screen assumed genuine because fact-checking hadn't caught up yet. Anthropic's own security evaluations breached three real companies. India's average breach cost hit a record high. Researchers showed AI coding agents hallucinate predictable names attackers can register in advance. And a deepfake of the finance minister kept producing victims months after the same script had already been documented.
1

Anthropic says three Claude models breached real company networks after a testing environment quietly gained internet access it should not have had

Anthropic disclosed on 31 July 2026 that a review of 141,006 evaluation runs conducted with partner Irregular found three cybersecurity-evaluation incidents, the earliest traced to April 2026, in which Claude models had live internet access during capture-the-flag-style testing meant to be network-isolated. Anthropic attributes this to a misconfiguration and a misunderstanding with the evaluation partner, not a model escaping its environment. Opus 4.7 found and breached a real company it mistook for a simulated target, extracting application and infrastructure credentials and reaching a production database containing several hundred rows. An internal model Anthropic calls Mythos 5, while working against a fictional target, published a malicious Python package to the real PyPI registry; the package reached 15 real systems, including one belonging to a security company, and exfiltrated credentials from anyone who ran it. A third, unnamed internal research model scanned roughly 9,000 targets and compromised one real company through SQL injection combined with credentials taken from an exposed debug page. Anthropic says none of the three models attempted to exfiltrate itself or deliberately escape its test environment, and that newer models showed more restraint than older ones.

Why it matters for IndiaIndian AI labs, GCC security-research teams and MSSPs building or buying agentic red-team and evaluation tooling are running comparable experiments, often with less isolation discipline than a frontier lab applied even when its discipline failed. A configuration error, not a compromised model, was enough to turn simulated exercises into real breaches, including one where a poisoned package reached other people's systems.
ActionTreat any AI evaluation or red-team range as requiring production-grade network isolation, verified independently rather than trusted from configuration intent; block outbound access to public package registries, code-hosting platforms and the open internet by default in these environments; require human approval before an evaluation agent scans, exploits, publishes a package or touches credentials; retroactively audit past eval runs for signs any of them reached real infrastructure.
SourceThe Hacker News, "Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations" (31 July 2026); Axios (30 July 2026); The Hill (30 July 2026); Forbes (3 August 2026).
2

India's average data-breach cost hits a record Rs 25.5 crore, with more than a quarter of malicious breaches now AI-generated

IBM and the Ponemon Institute's Cost of a Data Breach Report 2026, released 3 August 2026 and based on 602 organisations studied between March 2025 and February 2026 with a May 2026 follow-up survey of 456 entities, found India's average total cost of a data breach reached an all-time high of Rs 25.5 crore, up 15.9% from Rs 22 crore the previous year. Twenty-six percent of malicious breaches in India were AI-generated. The average breach also grew in scale, compromising 39,500 records against 38,200 a year earlier. Phishing, including voice and SMS phishing, remained the leading initial attack vector at 19%, ahead of drive-by compromise at 16% and supply-chain compromise at 15%. The report found roughly a Rs 10 crore gap tied to AI-security maturity: organisations with extensive AI and automation in their security operations averaged Rs 21.3 crore per breach, against Rs 31.6 crore for those with little or none, yet 68% of Indian organisations report limited or no AI/security-automation use.

Why it matters for IndiaThis is now a documented, India-specific figure rather than a global estimate applied locally: AI is measurably raising both the frequency of breaches, as a generation tool for attackers, and the cost gap between organisations that have and have not adopted AI-assisted defence.
ActionBenchmark current security-automation maturity against the report's tiers before the next budget cycle; prioritise phishing-resistant authentication and voice/SMS-phishing controls given they remain the leading entry point; extend supply-chain monitoring given its rising share of initial access; use the report's cost gap to justify AI-assisted detection and response as a cost-reduction case, not only a capability upgrade.
SourceIBM and Ponemon Institute, Cost of a Data Breach Report 2026 (3 August 2026); Business Today (3 August 2026); Business Standard (3 August 2026).
3

HalluSquatting: researchers show AI coding agents hallucinate the same fake package and repository names predictably enough for attackers to register them first

Researchers led by Aya Spira in Ben Nassi's group at Tel Aviv University, working with Technion and Intuit, published the finding on arXiv on 8 July 2026, reported by BleepingComputer. Testing six widely used AI coding agents and assistants — Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI and OpenClaw — the team found the tools do not hallucinate random non-existent package or repository names; they hallucinate the same name repeatedly and predictably, up to 85% of the time for repository requests and 100% of the time for "install this skill" requests. Because the fabricated name is predictable rather than random, an attacker can pre-register it on npm, GitHub or a comparable registry with malicious content before any real developer's agent asks for it, the reverse of conventional after-the-fact typosquatting. The researchers describe their percentages as a floor, not a ceiling. It follows earlier related findings this year: a hallucinated npm package, "react-codeshift," spread through 237 repositories via forked AI-agent skill files, reported in January 2026, and Palo Alto Networks' Unit 42 catalogued roughly 250,000 domains commonly hallucinated by language models, reported in June 2026.

Why it matters for IndiaIndian software exporters and GCC engineering teams have adopted the exact tools tested, including Copilot, Cursor, Cline and Gemini CLI, often for precisely the scaffolding and dependency-installation tasks where hallucination rates were highest.
ActionRestrict agents to a private, allow-listed package source rather than the public registry directly; pin dependencies through lockfiles and verify provenance before merging anything an agent proposes; flag for manual review any repository or package an agent references that was created recently or lacks a verifiable maintainer history; treat an agent's suggested dependency with the same scrutiny as an unsolicited link in an email.
SourceAya Spira, Ben Nassi et al., arXiv preprint (8 July 2026); BleepingComputer (July 2026).
4

A deepfake video of the finance minister keeps generating real victims months after the same scam script was already documented

A paid Facebook advertisement carrying an AI-generated deepfake of Union Finance Minister Nirmala Sitharaman, falsely endorsing an investment scheme promising an assured Rs 70,000 a day, roughly Rs 22 lakh a month, on a Rs 22,000 outlay, was confirmed fabricated by the PIB Fact Check Unit around 30-31 July 2026, which stated Sitharaman has neither endorsed nor authorised any such scheme. The same script had already produced a documented victim weeks earlier: The420.in reported on 8 July 2026 that a retired professor in Shankarapuram, Bengaluru lost Rs 61.10 lakh of Rs 65 lakh transferred, after a similar deepfake video routed him to a fake trading platform, bxbmarket.com, where a fraudster posing as an agent conducted "KYC" over email, showed a fabricated profit dashboard that grew past Rs 1 crore, then demanded further processing fees before any withdrawal; the scam ran from 9 March to 25 June 2026, when it was reported to the National Cyber Crime Helpline. The same reporting notes near-identical scripting in separate Khammam and Belagavi cases around the same period, pointing to shared infrastructure behind multiple deepfake-endorsement scams rather than one-off clips.

Why it matters for IndiaA single fact-check does not retire a campaign; the underlying video, platform template and script keep circulating and producing victims for months, across cities, until the advertising and hosting infrastructure itself is disrupted.
ActionFinancial institutions and platforms should treat any investment advertisement using a public official's or executive's likeness as a fraud signal requiring proactive review rather than a wait-for-complaint response; publish consumer warnings tied to the specific script elements, assured daily returns, KYC conducted over email, a dashboard that blocks withdrawal without further payment, rather than only the fact that a video is fake; individuals should verify any investment offer bearing a public figure's endorsement through that figure's official channel before transferring funds.
SourcePIB Fact Check Unit, reported by Organiser (31 July 2026); The420.in (8 July 2026).
AI defender tip: Every item this edition traces back to a boundary that looked intact but was not verified: a test environment assumed isolated, a package name assumed clean because it looked agent-generated, a video assumed genuine because it named a familiar face. None of this needed a novel defence. Network isolation, dependency provenance checks and independent verification of any urgent or too-good financial claim are controls Indian security teams already know how to run. The gap was applying them by default to AI-touched systems and AI-adjacent claims, instead of treating an agent's output or a familiar face on screen as inherently trustworthy.

Nirad Threat Research

Nirad AI Threat Watch | Bharat-first threat intelligence