The Mythos Moment: What Anthropic’s Most Dangerous Model Means for India’s BFSI Cyber Stack | Episode 84
Every few quarters, something arrives in the AI world that forces you to stop whatever model of the industry you were carrying in your head and redraw it from scratch. Mythos is that one.
Every few quarters, something arrives in the AI world that forces you to stop whatever model of the industry you were carrying in your head and redraw it from scratch. For me, that moment this month was reading the system card of Anthropic’s new frontier model, Mythos. I had expected another incremental leap, a few benchmarks crossed, another round of capability scaling headlines. What I got instead was a 244 page document describing a model that can autonomously complete a 32 step corporate network attack, found a vulnerability in OpenBSD that had hidden for 27 years, and in some rare cases wrote fake reasoning in its chain of thought to conceal what it was doing.
If you are reading this and thinking, fine, but what does that have to do with Indian fintech and BFSI, I would encourage you to keep reading. Because the answer, as I will try to lay out here, is that it has everything to do with us. India has become the second most targeted country in the world for email-based cyber threats, our BFSI sector faced an average of 4.1 million attacks every month in the first half of 2025, and the DPDP Act has just turned data breach negligence from a PR problem into a penalty of up to INR 250 crore. The arrival of a model like Mythos, and the next one after it, changes the risk calculus for every bank, NBFC, insurer, fintech and infra provider in the country.
In this episode, I want to do three things. First, decode what Mythos actually is and why Anthropic themselves described it as carrying the greatest alignment risk of any model they have released. Second, translate that capability into what it means for India specifically given our regulatory stack, our legacy tech debt and our threat geography. Third, map the Indian cybersecurity startup and VC funding landscape that is quietly emerging as one of the most important bets in the BFSI infrastructure space.
A quick acknowledgement of the source. Much of the framing on Mythos capabilities draws from Michael Cembalest’s April 2026 Eye on the Market note at JP Morgan. His work does an excellent job of distilling Anthropic’s own system card, and I would recommend reading it. What I am trying to add here is the India overlay, which I believe is missing from most of the global analysis I have come across.
EMPLOYMENT AND INVESTMENT DISCLAIMER
I am an investor at UNLEASH Capital, a fund focused on Fintech and BFSI investments in India. Our fund is 100 percent backed by Japanese capital. Views expressed in this newsletter are personal, based on public information and my own industry conversations, and do not constitute investment advice or a representation of UNLEASH Capital’s official positions. We may have, or be evaluating, investments in companies mentioned here. Please do your own due diligence.
1. What is Mythos, and why is Anthropic itself nervous?
Anthropic describes Mythos as both its best aligned model to date and the model that likely poses the greatest alignment related risk of any they have released. That contradiction is not a marketing gaffe. It is a genuine description of where frontier AI has arrived. The safety work has improved, but the underlying capability has grown faster than the safety work.
The model was trained on Google TPUs, has not been released to the general public, and was made available to a select group of 12 partner organisations under what Anthropic calls Project Glasswing. That partner list is worth pausing on. It includes Amazon, Apple, Broadcom, Cisco, CrowdStrike, Google, JP Morgan, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks, along with Anthropic themselves. Notice what is not there. No Indian company. No Indian bank. No Indian fintech. No Indian cloud or cybersecurity provider.
This is the first data point I want the reader to carry forward. The companies that get to use a frontier model like Mythos to proactively find and patch vulnerabilities in their own codebases, their vendor software and their open source dependencies will get a head start of unknown duration over everyone else. That head start is now closed to Indian institutions unless they work through partners or wait for trimmed down public versions.
Capability, in four charts
Before getting into the India angle, it helps to anchor on what the model can actually do. The Anthropic system card disclosed benchmark scores across browsing, coding, factuality and general reasoning. The pattern is consistent.
Mythos versus prior Claude models on key benchmarks
Accuracy or composite index score, higher is better
Source: Mythos System Card (April 2026)
The BrowseComp score, 87 percent at a modest 3 million tokens, is meaningful because browsing plus synthesis is exactly the workflow that an attacker running open source intelligence on a target bank or fintech would use. The SWE Bench Pro result shows that even when controlling for memorisation of training data, Mythos holds an 80 plus percent pass rate on complex software engineering tasks where prior Claude models collapse to the 50 percent range. This is the capability that translates most directly into the ability to find and exploit vulnerabilities.
On the Epoch Capabilities Index, which aggregates 40 separate AI benchmarks, Mythos bends the the Anthropic trend line upward, almost like a J curve.
The cybersecurity capability is the part that should worry a CISO
Now for the chart that in my view should be circulated in every CISO office in the Indian BFSI sector this quarter. The UK AI Security Institute put Mythos, Opus 4.6 and GPT 5.4 through a 32 step corporate network attack simulation. The steps span initial reconnaissance, lateral movement, credential theft, wiki exploitation, web application compromise, command and control reverse engineering, advanced persistence, infrastructure compromise and full network takeover.
Completed attack steps versus tokens spent, 32 step corporate network simulation
Higher line means the model autonomously completed more stages of a full kill chain
Source: UK AI Security Institute, April 13, 2026
Mythos, in its best iteration, completed all 32 steps. No frontier model had done this before. On average, Mythos completed 22 steps versus 16 for Opus 4.6 and 14 for GPT 5.4. On Anthropic’s own CyBench benchmark, Mythos scored 100 percent, essentially saturating the test. On Firefox zero day detection, Mythos had a 72 percent shell exploitation success rate versus 1 percent for Opus 4.6 and 0 percent for Sonnet 4.6.
The examples Anthropic has made public are equally striking. A vulnerability in OpenBSD that had escaped detection for 27 years. A flaw in the video encoder FFmpeg that had slipped through 5 million previous automated tests. Vulnerabilities in the Linux kernel that would allow complete machine takeover. AI security researcher Nicholas Carlini, who joined Anthropic a year ago, said he has found more bugs in the last few weeks than in the rest of his career combined.
The important detail here is that this cyberhacking skill is emergent. The model was not purpose built for offensive security. It is a byproduct of scaling general reasoning and code capabilities. This has an uncomfortable implication. Every subsequent frontier model from every frontier lab, including in jurisdictions with weaker export controls, is likely to inherit and exceed this capability whether its creators design for it or not.
WHAT I AM TAKING AWAY AS AN INVESTOR
Three things.
First, offensive cyber capability is now ambient in every frontier model, not a specialist product.
Second, the defensive side of the market gets a window of roughly 12 to 18 months, the period during which Project Glasswing style patching programmes run ahead of adversarial capability.
Third, every enterprise software vendor in India is about to be audited by an AI whether they like it or not. Some by defenders. Some by attackers.
2. The India threat context, which is worse than most people realise
If Mythos is the accelerant, India is already sitting on a substantial amount of dry wood. Let us go through the numbers.
The progression of CERT-In tracked cybersecurity incidents over the last decade tells a story that the market chatter on AI has largely drowned out.
CERT-In tracked cybersecurity incidents in India
Number of incidents per year
Source: CERT-In, NCRB, Trace Data Research, author compilation
From 44,679 incidents in 2014 to over 20 lakh incidents in the latest compiled year, the attack surface has exploded. The BFSI sector alone is now absorbing roughly 4.1 million attacks a month in 2025 per multiple industry reports, which works out to about 1.4 lakh attacks a day on banks, NBFCs, insurers, fintechs and brokers put together.
The BFSI specific picture
I have spent the last year or so in rooms with bank CIOs, NBFC CTOs and fintech founders thinking through cyber posture. A few uncomfortable patterns keep showing up.
Around 80 percent of Indian banks still rely on SMS OTP as the dominant second factor in multi factor authentication. SIM swap and phishing attacks exploit this every single day. Approximately 57 percent of Indian organisations have reported data breaches involving APIs since 2022. Over 85 percent of Indian mobile banking apps have been found to contain exploitable vulnerabilities in various audits. The average cost of an Indian data breach hit a record INR 22 crore in 2025 according to Seqrite’s analysis.
Here is a breakdown of the attack categories that Indian BFSI is actually dealing with, based on a synthesis of CERT-In, Resecurity, Cyberlaw Consulting and Eventus Security reporting.
India BFSI cyber incidents by category, 2025
Approximate share of reported incidents, industry synthesis
Source: Synthesis of CERT-In directives, Resecurity, Cyberlaw Consulting, Eventus Security, Seqrite India Cyber Threat Report 2026
The two categories that the Mythos class of AI will accelerate most, in my reading, are supply chain and vendor portal attacks, and API and web application exploitation. These are exactly the domains where automated vulnerability discovery at scale becomes unusually powerful. A model that can chain together multiple obscure software weaknesses, as Mythos has demonstrated, does not need to find a clever new attack. It just needs to find the one forgotten, unpatched, badly configured Jenkins server or Amazon S3 bucket that an Indian bank’s third party vendor is running.
The Nupay breach in 2025, which exposed 273,000 bank transfer documents through a misconfigured S3 bucket, is a perfect illustration of the class of incident that will become trivially automatable. So was the reported RansomEXX attack on Indian banking infrastructure through a compromised vendor Jenkins server.
The legacy tech problem is bigger in India than people admit
Cloud based IT is generally replaced every 4 to 5 years and patched regularly. Operational technology layers remain in service for 10 to 18 years. That is the global picture. The Indian version is arguably worse. Many public sector banks, cooperative banks, regional rural banks and even some mid tier NBFCs still run core banking stacks, ATM switch infrastructure and treasury systems on hardware and software layers that are a decade or more old. Upgrade cycles in these entities are budget constrained, audit driven and politically sensitive.
Estimated patchability of Indian BFSI technology layers
Percentage of installed base, indicative ranges
Source: Author analysis, adapted from JP Morgan Eye on the Market, April 13, 2026, with India overlay from RBI FSR, DSCI and industry conversations
The ranges here are indicative, not precise, but the directional read is what matters. For a typical mid sized Indian bank, roughly 55 to 65 percent of the tech estate is patchable on a modern cadence. 20 to 30 percent is effectively unpatchable without capex heavy modernisation. Somewhere between those sits the 12 to 20 percent zone that is patchable in theory but not in practice, because it is legacy software the vendor no longer actively supports, or because the workload cannot afford the downtime a patch would require.
This is the India specific attack surface that a model with Mythos class capabilities will feast on.
The China factor, and the geography of attacks
Anthropic reported that three Chinese AI companies, DeepSeek, Moonshot AI and mostly MiniMax, set up more than 24,000 fraudulent accounts on existing Claude models and prompted them over 16 million times. This was not a one off. It was sustained, coordinated exfiltration of capability into Chinese AI development pipelines.
From 2000 to 2023, China was responsible for 240 state sponsored or state affiliated cyberattack campaigns globally per the Mercator Institute for China Studies. The US was the top target at 184 identified campaigns. India is not behind in that map, and our specific geography of adversarial pressure goes beyond China. Seqrite’s India Cyber Threat Report 2026 documents APT campaigns attributed to actors in Pakistan, Bangladesh and the Middle East. Following the Pahalgam strike in 2025, Indian websites absorbed more than 1.5 million cyberattacks in a short window. During Operation Sindoor between May 7 and May 10, 2025, the President’s website absorbed roughly 19 hours of DDoS, and around 200,000 probing and attack attempts targeted the power grid.
Put this in an AI context. A state or state adjacent actor with access to a Mythos capable model, running against legacy Indian infrastructure with inconsistent patching and vendor sprawl, is not going to struggle for targets. The mismatch between attacker tooling and defender tooling is wider in India than it is in the US or EU.
A closer look at some 2025 Indian incidents
It helps to pin this abstraction to actual incidents. A few that stood out from the 2025 Indian calendar.
The Nupay breach in 2025 exposed roughly 273,000 bank transfer documents through a misconfigured Amazon S3 storage bucket. The fintech later confirmed it had addressed a configuration gap. The relevant point is that this was a fintech operating in the payments aggregation space, which means that the exposure touched multiple upstream banks and downstream merchants. Under the DPDP regime that was not yet fully in force, the financial consequence was mild. Under the current regime, a similar incident would trigger notification to the Data Protection Board, potential DPDP penalties and parallel RBI action.
A malware incident targeting a third party vendor portal associated with ICICI Bank was reported in 2025, with the Bashe ransomware group claiming responsibility. The bank did not confirm the scope. The pattern is what matters. This was not a direct attack on ICICI infrastructure. It was an attack on a vendor access pathway that then acted as a conduit. Indian BFSI has been vulnerable to this exact pattern repeatedly.
During Operation Sindoor in May 2025, which followed the Pahalgam terror strike, a coordinated wave of cyber activity hit Indian government and critical infrastructure simultaneously. The impact included approximately 19 hours of DDoS targeting the President’s website, around 200,000 probing and attack attempts on the power grid, website defacements across ministries and public service portals and attacks against NIC. CERT-In issued warnings to the BFSI sector about Pakistan linked APT groups running ransomware, supply chain intrusions, DDoS, website defacements and malware against Indian financial institutions. The Bombay Stock Exchange itself issued a cybersecurity advisory.
A RansomEXX attack on Indian banking infrastructure in mid-2025 reportedly ran through a compromised Jenkins server at a vendor, illustrating again how supply chain compromise is the dominant attack vector. The negotiation with the ransomware group reportedly went on for weeks.
Star Health and Niva Bupa faced escalating extortion campaigns in 2025, with threat actors alleged to have sent physical threats including bullet cartridges to executives following earlier data exposure. The sophistication and brutality of these campaigns is a reminder that cybercrime and physical threats are now blending, particularly in sectors like health insurance where data is highly personal.
And in early 2026, Sinobi and KaruHunters ransomware activity against India based IT services companies has continued the trend from 2025, with Sinobi in particular emerging as one of the most active ransomware groups globally with around 50 claimed victims by January 2026.
The common thread across all these is not novelty of attack technique. It is scale, persistence and the ability to chain together low sophistication weaknesses into a high impact outcome. That is exactly the workflow that a Mythos class model automates at a token cost that is going to keep falling.
3. The regulatory stack finally caught up. And that changes the buying behaviour.
Every conversation I have had with Indian cybersecurity founders over the last 18 months has touched on the same turning point. The DPDP Rules were notified on 13 November 2025. For the first time, data protection non compliance in India carries a real, calibrated financial penalty.
The key provisions that matter for cyber posture:
• Penalty of up to INR 250 crore for breaches caused by inadequate security safeguards, and up to INR 200 crore for failure to notify the Board or affected Data Principals.
• 72 hour detailed breach report to the Data Protection Board of India, with initial intimation required without delay.
• Significant Data Fiduciary (SDF) obligations for entities the government designates based on volume, sensitivity and risk. These obligations include appointing an India based Data Protection Officer, appointing an independent data auditor, conducting Data Protection Impact Assessments and sharing periodic observations with the Board.
• Cross border transfer via a whitelist of trusted jurisdictions, which introduces real friction for multinational data flows.
CERT-In’s 2022 directions are still very much alive, layered underneath DPDP. These require incident reporting within 6 hours, 180 day log retention and NTP time synchronisation across systems. SEBI’s Cybersecurity and Cyber Resilience Framework applies to market entities and requires 6 hour detection to notification timelines. RBI’s Cyber Security Framework for Banks and the October 2025 directives on digital payment security sit on top of all of this.
The net effect is that a mid sized Indian bank or NBFC is now operating under at least 4 overlapping cyber reporting regimes. A fintech holding a payments aggregator licence or an insurance aggregator licence sits under 3 to 5 regulators for cyber questions alone.
India cybersecurity market size, 2023 to 2030 estimates
USD billion, blended forecast range from leading research firms
Source: Blend of IMARC, MarketsandMarkets, Mordor Intelligence, Grand View Research, 2025 and 2026 estimates; author synthesis
The Indian cybersecurity market sat somewhere between USD 8.5 billion and USD 12 billion in 2025 depending on which research house you believe. The forecast CAGR to 2030 ranges from 14.5 percent to 18 percent. Even at the midpoint, this is a USD 18 to 20 billion market by the end of the decade. For the BFSI segment specifically, which already accounts for about 24 percent of cybersecurity revenues in India, the number is large enough to support several venture backed category leaders.
WHAT THE DPDP RULES ACTUALLY CHANGED FOR PROCUREMENT
Before DPDP, cybersecurity was sold into Indian BFSI as a risk reduction product. CIOs and CISOs bought it, but the CFO was rarely engaged. After DPDP, with penalties of up to INR 250 crore per breach and Data Protection Officer liability sitting on named individuals, cyber budgets are being discussed at CFO and board level. That is a material change in buying behaviour and a tailwind for every founder selling into this stack.
4. The Indian cybersecurity startup map, and where VC money is actually going
Let me now get to the part I am asked about most. Who is building what, how much capital has flowed in, and where do I personally think the next large outcomes are hiding.
The lay of the land
India has over 400 cybersecurity startups according to most industry counts, employing around 650,000 cybersecurity professionals across startups, system integrators, GCCs and in-house BFSI teams. Despite this workforce, there are still an estimated 25,000 to 30,000 open cybersecurity roles, a talent gap that is up roughly 30 percent from 2023. That gap is itself a business opportunity for managed detection and response players.
Here are some of the most relevant Indian startups in the space, mapped by functional category.
This is not a complete list, and the categorisation is necessarily loose because many of these companies span multiple segments. But directionally, you can see that Indian cyber is now credible across at least six distinct layers: threat intelligence, SOC and XDR, risk quantification, attack surface management, identity and zero trust, and payments plus BFSI specific security.
The funding story, global and Indian
Globally, cybersecurity startup funding hit USD 18 billion in 2025 per Crunchbase, up 26 percent from 2024, and the third highest annual total in a decade. Early stage funding in particular surged 63 percent year on year to around USD 7.5 billion across Series A and B rounds, driven almost entirely by the intersection of AI and security. Q1 2026 alone saw USD 2.7 billion go into VC backed cyber startups. 2025 M&A in the space topped USD 9.2 billion across 120 deals.
Global cybersecurity VC funding, 2020 to Q1 2026
USD billion, seed through growth stage
Source: Crunchbase, Cybersecurity Ventures, Q1 2026 data
India’s share of that pool is still small but rising. Based on Tracxn, Inc42 and company announcement data, Indian origin cybersecurity startups have raised somewhere between USD 200 million and USD 300 million across 2024 and 2025 combined, a fraction of the global pool but material growth from 2022 levels. Some of the more significant recent rounds:
• Safe Security raised a USD 70 million Series C in 2024, led by new and existing investors including BT Group, Cisco Investments and Susquehanna Asia VC, building on the earlier USD 33 million BT led round.
• CloudSEK raised USD 19 million in its Series B1 in May 2025 led by MassMutual Ventures with Commvault, Inflexor, Prana Ventures and Tenacity Ventures participating, followed by a USD 10 million Series B2 in January 2026 that made it the first Indian origin cybersecurity company to receive investment from a US state venture fund (Connecticut Innovations).
• Sequretek raised a USD 8 million Series A led by Omidyar Network in late 2023 and has been operating profitably since.
• Exium, a cybersecurity startup with Indian roots, was acquired by Netgear in June 2025.
Indicative Indian cybersecurity startup funding, 2022 to 2026
USD million, disclosed rounds for Indian origin companies
Source: Author compilation from Tracxn, Inc42, YourStory, company press releases
The pattern here is that India is underpenetrated relative to both its threat surface and its regulatory tailwind. A BFSI sector absorbing 4.1 million attacks a month, with a DPDP regime that can levy INR 250 crore penalties, and a cybersecurity market approaching USD 20 billion by 2030, is currently being served by a startup ecosystem that has raised well under USD 300 million across its entire Indian origin VC backed cohort. That gap is the opportunity.
Where I personally think the next category winners will emerge
Based on our conversations at UNLEASH Capital with founders and BFSI CIOs over the last year, here is how I think about the investable sub-segments.
First, BFSI specific SOC and detection plus response. Indian banks and NBFCs cannot buy a purely US centric SIEM and expect it to work. The alert taxonomies, the regulatory reporting formats, the vendor ecosystem and the language of the analyst queues are different. Sequretek is the leader here, but the market is large enough to support 3 to 4 platforms. Expect MDR and SOC as a service revenue to grow at a blended CAGR in the high teens through 2030.
Second, attack surface and vendor risk management. If there is one class of product that directly answers the Mythos threat vector, it is this. Automated discovery of all internet facing assets of a bank, its subsidiaries, its vendors and its vendors’ vendors. CloudSEK and FireCompass are credible here. The gap is in the mid market banks and cooperative banks, which cannot afford the global incumbents like BitSight or SecurityScorecard.
Third, identity and fraud at the UPI layer. India processes more than 16 billion UPI transactions a month. Every one of those is a potential mule account, phishing vector or deepfake social engineering attempt. The opportunity is to build an AI native fraud and identity platform that can operate at that volume. Zero Defend Security’s deepfake detection product launched in March 2025 is an early signal.
Fourth, DPDP and compliance automation. Every data fiduciary in India now needs a consent management system that can integrate with registered Consent Managers, produce audit ready dashboards, handle 72 hour breach reporting workflows, and manage cross border transfer whitelists. This is a regulatory tech opportunity that is being addressed by both pure play startups and larger fintech infra players extending into the space.
Fifth, OT and critical infrastructure security. India’s power, telecom and transport infrastructure sits in the same patchability gap I described earlier. A small but growing set of deep tech founders are building here. Pantherun’s hardware level encryption is one example. These are harder businesses to scale given long sales cycles but have durable moats once embedded.
Sixth, AI security itself. Indian enterprises deploying LLMs in production now need tools for prompt injection defence, model red teaming, data leakage prevention through AI endpoints and governance over agentic workflows. This is a nascent category globally and even more so in India, but the buyers are already asking for it.
Indian cybersecurity segment attractiveness, author view
Qualitative scoring, 1 = low, 5 = high, based on market size, regulatory tailwind and competitive intensity
Source: Author’s view
A REALITY CHECK
Cybersecurity is a hard category to build in from India. Sales cycles are long. Reference customers demand incumbency. Global distribution requires a US or EU office and sales leadership that is expensive. Product moats erode quickly when incumbents copy. A founder building here needs conviction, patient capital and a willingness to spend 18 to 24 months proving a product with a small cluster of Indian BFSI customers before scaling. The silver lining is that DPDP and the threat environment just turned the top of the funnel on.
5. What banks, NBFCs and fintechs should be doing over the next 12 months
I want to move from the market lens to the operator lens briefly. If you are running technology or risk at an Indian financial institution, here is a practical prioritisation that I think holds up in the Mythos era.
Priority 1, vendor and supply chain risk
Mythos class models are disproportionately good at finding weaknesses in software dependencies. The Nupay, BORN Group and ICICI vendor portal incidents of 2025 all followed the same pattern. The attacker did not break into the main institution. They broke into a third party, then rode the integration in. An Indian bank today typically has anywhere between 150 and 600 active vendors with some form of system integration or data access. Most of them were onboarded through point in time security assessments that are functionally useless in a continuous threat environment.
The specific asks I would make of every BFSI CIO this quarter. Run an automated external attack surface discovery across every active vendor, not just the top tier. Move vendor security reviews from annual SOC 2 attestations to continuous monitoring. Include in every vendor contract a 6 hour incident notification clause that matches CERT-In requirements. Segment vendor access so that a breach in one cannot laterally move into the production core banking environment.
Priority 2, API and mobile app security
The 57 percent of Indian organisations reporting API related breaches since 2022, and the 85 percent of mobile banking apps found to contain exploitable vulnerabilities, is not a statistic that will get better on its own. Every new product launch in Indian BFSI adds 5 to 15 new API endpoints. Most of them are not being continuously tested.
Implement API discovery as a first class function in your security operations centre. Add runtime API threat detection, not just pre production scanning. Commission independent red teams to test mobile apps against the OWASP mobile top 10 at least twice a year.
Priority 3, DPDP operational readiness
The 72 hour breach notification window is tight. The 6 hour RBI window for payment system operators is tighter. You cannot meet these windows without pre-wired playbooks. The Data Protection Officer role, where mandated for a Significant Data Fiduciary, is not a compliance checkbox. It is an operationally critical role that should report to the board, not the CIO.
Build pre-approved breach notification templates. Pre negotiate relationships with external forensics firms so you do not spend the first 24 hours of an incident shopping for one. Run at least one full tabletop exercise per year that simulates a breach and rehearses the DPDP plus CERT-In plus RBI reporting workflow end to end.
Priority 4, AI security governance
If your bank or NBFC is deploying generative AI in any customer facing or credit decisioning workflow, you need an AI security policy that covers prompt injection, training data governance, model output monitoring and red teaming. RBI’s ongoing focus on model risk in digital lending makes this less of an option and more of a requirement.
Priority 5, cyber insurance and capital buffer
Cyber insurance penetration in Indian BFSI is still low by global standards. A data breach now carries a worst case INR 250 crore DPDP penalty plus regulatory action plus reputational cost plus customer remediation plus potential class action exposure. The capital adequacy conversation needs to start including a cyber loss scenario.
6. Wrapping up
Let me come back to where I started. Anthropic named their most dangerous model Mythos and released 244 pages of documentation explaining why it worries them. They then gave 12 carefully selected global partners privileged access to use it defensively, charged them USD 25 per million input tokens and USD 125 per million output tokens, and offered USD 100 million in usage credits to offset the cost.
The optimistic read is that there are a finite number of important software vulnerabilities in the world, and if a safety focused lab runs its model against them first, the long term ecosystem ends up safer. Anthropic’s own Sam Bowman said working with this model has been a wild ride, that they have come a long way on safety but expect the next capability jump of this scale to be a huge challenge. That is a measured statement from someone who is clearly worried.
The less comfortable read is that the US had a monopoly on nuclear weapons between 1945 and 1949. Since then we have lived in a multipolar world. The same thing will happen with frontier AI capability. It is not a question of if, but of when, a state or non state actor without Anthropic’s alignment priorities builds a Mythos equivalent. When that happens, the defenders that have already used Project Glasswing class access to patch their own and their vendors’ software will have a meaningful head start. Those who have not will be exposed.
India sits in a complicated position. We are a top three cyber target globally. We have the world’s largest digital public infrastructure. We run the world’s largest real time payments system. Our BFSI sector is the single most attractive attack surface in Asia after China. Our startups are building capable products, but our domestic cybersecurity capital pool is a fraction of the opportunity. Our regulators have, finally, given the system the financial backing to force a change in buying behaviour.
From where I sit, this is a moment that favours three kinds of people. Founders who are building BFSI native cybersecurity and compliance products with a clear wedge into Indian banks, NBFCs, insurers and regulated fintechs. Operators inside financial institutions who treat cyber as a capex line and a board level topic, not an IT expense. And investors who can underwrite long sales cycles, dual market (India plus global) go to markets, and technical founders building in a category that will take a decade to fully play out.
A bit of reflection, a bit of prediction, and a lot of conviction that the next 10 years of Indian BFSI will be shaped as much by what happens in cybersecurity as by what happens in credit or payments. The Mythos moment is a useful marker. It will not be the last one.
As always, if you are a founder building in cybersecurity, compliance, fraud detection, identity, AI security or any adjacent BFSI infrastructure category in India, please do reach out. We at UNLEASH Capital spend a lot of time in this space, and I am always happy to have a conversation. You can find me at abhishek.kumar@unleashcp.com.
Disclaimer: The views expressed in this article are personal and do not reflect the views of my employer or any organization I am associated with. This is not investment advice. Please do your own research before making any investment decisions.
Reach out if you want to discuss anything in fintech. Would love to be connected. If you enjoyed this episode, please share it with colleagues and friends who work in banking, fintech, or AI. And hit subscribe if you have not already.
© 2026 Abhishek Kumar · Indiafintech











