Founded in 2008 · Built for AP professionals · Community-led · Practical guidance, not sales fluff
BreakingNACHAAI AutomationVendor FraudJobsCertifications
Friday, July 10, 2026
Updated
Accounts Payable Professionals Group
Practical intelligence for the people who keep business moving
Accounts Payable news, controls guidance, automation coverage, career resources, and professional insight built for the people doing the work.
Popular now AP automation Fraud controls Vendor management Career development Why APPG exists →
Leadership
APPG appoints Mariann Ruhno as Chief Education Officer
Mariann Ruhno will help guide future APPG courses, certifications, and educational resources designed for working Accounts Payable professionals. Read the announcement →
Rules & Compliance
NACHA fraud monitoring Phase 2 took effect June 22, 2026
Volume thresholds are gone. All non-consumer Originators, TPSPs, and TPSs must now monitor for fraud, while RDFIs must screen incoming credits. Read the APPG update → Official NACHA summary →
Start here
APPG
01
Join the professional community
Connect with AP professionals, leaders, vendors, and job seekers.
Visit the LinkedIn group →
02
Get practical AP updates
Receive useful news, controls guidance, career resources, and process ideas.
Join the newsletter →
03
Find your next AP opportunity
Browse roles selected for Accounts Payable and finance operations professionals.
Browse AP jobs →
Join the APPG community
Practical AP content. No clutter. No generic finance noise.

Saturday, April 11, 2026

Anthropic Mythos Ai Cyber Risk Banks AP

Skip to article body
Controls & Risk

Anthropic Mythos 5 and the New AI Cyber Risk Facing Banks and Accounts Payable

Anthropic’s Mythos models have moved from a restricted research preview into a broader defensive cybersecurity program. The latest developments make the implications for banks, payment systems, and Accounts Payable more concrete.

By Robert Ruhno
Executive Director, Accounts Payable Professionals Group
Published
Updated
Updated July 10, 2026: This article now includes the launch of Mythos 5, Project Glasswing’s international expansion, Anthropic’s reported vulnerability findings, temporary U.S. access restrictions, restored access, new safeguards, and a recent government cybersecurity case study.
AI cyber risks affecting Accounts Payable workflows, banking systems, and payment infrastructure
Illustration: AI-driven cybersecurity risks across banking and Accounts Payable systems.

Mythos and Project Glasswing Timeline

April 7, 2026
Anthropic announces Project Glasswing and introduces Claude Mythos Preview .
April 10, 2026
Reuters reports that Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell warned major bank CEOs about cybersecurity risks tied to Anthropic’s new model.
May 22, 2026
Anthropic reports that it and approximately 50 Project Glasswing partners identified more than 10,000 findings they classified as high or critical severity. The company says the bottleneck is shifting from finding vulnerabilities to verifying, disclosing, and patching them.
June 2, 2026
Anthropic expands Project Glasswing to approximately 150 additional organizations in more than 15 countries, bringing the reported partner network to roughly 200 organizations.
June 8, 2026
Anthropic publishes research on how advanced AI could accelerate the development of exploits for known but incompletely patched vulnerabilities, often called N-days.
June 9, 2026
Anthropic launches Claude Mythos 5 for a small group of vetted cybersecurity defenders and infrastructure providers participating in Project Glasswing.
June 12, 2026
Anthropic suspends access to Mythos 5 and Fable 5 after receiving a U.S. government directive restricting access by foreign nationals.
July 1, 2026
Anthropic restores Mythos 5 access to a limited group of approved U.S. organizations after the government lifts the export controls.
July 2, 2026
Anthropic publishes additional information about its cybersecurity classifiers and proposes a framework for evaluating the severity of AI jailbreaks.
July 6, 2026
Anthropic publishes a case study reporting that the Government of Alberta used Claude to scan 466 million lines of code in 20 hours and help identify and remediate security gaps.

There are moments when technology improves gradually, and then there are moments when it changes the rules of the game.

Anthropic’s Mythos work appears to be an important step in that second category.

Anthropic introduced Claude Mythos Preview as part of Project Glasswing . Anthropic described the unreleased model as unusually capable at computer security tasks, including identifying and exploiting serious software vulnerabilities under controlled conditions.

The company did not release Mythos Preview broadly. Instead, it gave selected technology companies, infrastructure providers, open-source organizations, and security teams restricted access so they could use the model defensively.

That should matter to Accounts Payable professionals because AP sits directly on top of the systems that approve, transmit, and record money.

Why this matters:
AP teams may not manage cybersecurity directly, but they depend on bank portals, ERP systems, payment integrations, browsers, cloud applications, vendor portals, and approval workflows. If those systems become easier to attack, AP becomes part of the blast radius.

What Changed After the Original Article Was Published

The April announcement was initially about the potential of a restricted model. The developments since then have provided more evidence of the scale, the defensive opportunity, and the control challenges.

May 22, 2026

More Than 10,000 Reported Findings

Anthropic reported that it and its initial Glasswing partners identified more than 10,000 high or critical-severity findings across important software systems.

That number is Anthropic’s report, not an independent audit of every finding. Even so, it illustrates the operational challenge created when automated discovery moves faster than human validation and patching.

June 2, 2026

Glasswing Expands Internationally

Anthropic added approximately 150 organizations in more than 15 countries to the program. The expansion included organizations supporting power, water, healthcare, communications, hardware, and other critical infrastructure.

June 8, 2026

AI Accelerates Known-Vulnerability Exploitation

Anthropic reported that Mythos Preview could turn a collection of known software patches into working exploit attempts much faster than traditional manual research.

This raises the importance of applying critical security patches promptly once vendors make them available.

June 9 to July 1, 2026

Mythos 5 Launches, Pauses, and Returns

Mythos 5 replaced Mythos Preview for a small group of vetted cyberdefenders. A June 12 U.S. directive led Anthropic to disable access temporarily.

By July 1, limited access had been restored for approved U.S. organizations after the restrictions were lifted.

July 2, 2026

Safeguards Become Part of the Story

Anthropic published additional information about the classifiers used to block dangerous cybersecurity requests and proposed a common framework for evaluating the severity of model jailbreaks.

July 6, 2026

A Government Cybersecurity Case Study

Anthropic reported that a Government of Alberta team used Claude to scan 466 million lines of code in approximately 20 hours, identify vulnerabilities, support remediation work, and build additional security tools.

This case study shows the defensive side of the same technology: organizations may use advanced AI to examine large systems much faster than a traditional manual review.

Important distinction:
Finding a vulnerability is not the same as successfully exploiting it. Reporting should distinguish between discovery, validation, exploit development, and confirmed compromise.

What Makes This Different

Cyber threats are not new, and software vulnerabilities are not new. What appears to be changing is the speed, the scale, and the automation.

Traditionally, finding a serious vulnerability required time, specialized expertise, and patient manual investigation. Developing a working exploit required additional technical skill and testing.

Advanced AI can compress parts of that process. A model may be able to inspect code, reason through system behavior, identify a weakness, and help a trained user develop a test or proposed fix much faster than before.

The risk is not only that vulnerabilities exist. It is that the time between disclosure, exploit development, and active attack may continue to shrink.

“This is not necessarily a panic-now event. It is a warning that the defensive timeline is getting shorter.”

Why Banks and Regulators Paid Attention

Reuters reported that Treasury Secretary Scott Bessent and then-Federal Reserve Chair Jerome Powell warned major bank CEOs about potential cybersecurity risks associated with Anthropic’s new model.

Banking infrastructure depends on shared technology, including operating systems, browsers, cloud services, APIs, authentication tools, internal applications, and third-party software libraries.

If AI systems can identify weaknesses across that stack faster than before, banks and the organizations that rely on them may have less time to assess and remediate exposed systems.

In June, The Associated Press reported that Mythos identified vulnerabilities in sensitive U.S. government systems during a controlled testing exercise within hours.

The official cited by AP specifically cautioned that this did not mean the model exploited those vulnerabilities within that same period.

Operational warning for AP:
Even when an organization is not using Mythos or another advanced cybersecurity model, its AP workflows still depend on banks, software vendors, cloud providers, browsers, and integrations affected by the faster threat cycle.

Where Accounts Payable Fits Into the Picture

Accounts Payable is no longer a stand-alone back-office paperwork function. In many organizations, AP operates through a connected ecosystem of systems, credentials, data, and approvals.

AP ecosystem at a glance
ERP or Accounting System
Invoice Automation
Vendor Portals
Banking and Treasury Portals
API Integrations
Approval Workflows

This puts AP close to the software layers through which vendor data is changed, invoices are approved, and payments are released.

In practical terms, AP may become a meaningful target area in a future wave of faster, AI-assisted cyberattacks.

What This Could Look Like in the Real World

1. Payment Workflow Compromise

A weakness in a browser session, identity layer, plugin, or integration could be used to interfere with payment approvals or access controls.

2. Vendor Portal Manipulation

A serious supplier portal vulnerability could expose vendor records or allow unauthorized changes that normal AP review may not detect immediately.

3. API-Level Risk

Integrations between ERP systems, banks, payment platforms, and approval tools create efficient data paths. They can also create technical routes that attackers may attempt to exploit.

4. Faster Data Theft

Vendor master data, banking instructions, invoices, payment histories, and approval logs are valuable. AI may help attackers identify weak paths into those datasets more quickly.

5. Disruption Timed Around Critical Payment Periods

Attackers do not always need to shut down an entire company. Interrupting payment systems near payroll, month-end, quarter-end, or a major payment run may create enough pressure to cause mistakes or control bypasses.

The Patch Gap Is Becoming an AP Issue

Anthropic’s June research focused on N-day vulnerabilities, meaning flaws that have already been disclosed but are not yet patched everywhere.

Once a security patch is published, attackers can compare the old and new software versions to identify what changed. Advanced AI may make that comparison and the development of a working exploit faster.

For AP, the practical lesson is simple: software updates affecting bank access, browsers, ERP integrations, invoice automation, identity tools, and payment applications may become more urgent than they once appeared.

AP control lesson:
Accounts Payable should not install enterprise software independently, but it should know who owns patching for every payment-critical platform and how AP will operate if a system must be taken offline quickly.

What AP Teams May Notice

  • More frequent software patches and security notices
  • New multifactor authentication requirements
  • Shorter deadlines for applying critical updates
  • Temporary downtime for bank or AP platforms
  • Stricter controls around vendor changes and payment releases
  • More scrutiny of service accounts and API credentials
  • More questions from auditors, insurers, and security teams

Even when the threat feels technical or abstract, the operational consequences for AP may become very concrete.

The Defensive Opportunity

The same capabilities that may help attackers move faster can also help defenders identify weaknesses earlier. That is the central purpose of Project Glasswing.

Anthropic says participating organizations have used its models not only to find vulnerabilities, but also to suggest patches, test software before release, and help modernize older code.

The Government of Alberta case study provides a more recent example of this defensive opportunity. Anthropic reported that a small government team used Claude to examine hundreds of millions of lines of code in hours rather than attempting a manual review that could take years.

The remaining challenge is organizational capacity. A security team must still confirm that a reported vulnerability is real, determine its severity, coordinate disclosure, develop a safe fix, test that fix, and deploy it.

AI may accelerate discovery faster than organizations can complete those later steps.

What Accounts Payable Professionals Should Do Now

  • Review dual approval controls for high-value and high-risk payments.
  • Recheck vendor bank-change procedures and independent callback requirements.
  • Separate vendor maintenance, invoice processing, payment approval, and payment release duties where practical.
  • Limit banking and payment credentials to employees who need them.
  • Confirm that shared credentials are prohibited and service accounts are documented.
  • Ask who owns patching for the ERP, AP automation platform, bank portal, browser, and integration tools.
  • Maintain an emergency-payment procedure that does not abandon normal verification controls.
  • Include AP systems and payment runs in business-continuity and incident-response planning.
  • Treat unusual workflow behavior, unexpected login changes, and unexplained vendor-data changes as potential security events.
  • Preserve system logs and supporting documentation so suspicious activity can be investigated.

Questions AP Leaders Should Ask IT and Treasury

  1. Which AP and banking systems are considered payment-critical?
  2. How quickly can critical security patches be tested and deployed?
  3. What happens if a bank portal, ERP integration, or approval platform is unavailable during a payment run?
  4. Are privileged credentials, service accounts, and API keys reviewed regularly?
  5. Can the company identify who changed vendor banking data, when it changed, and who approved it?
  6. Does incident-response planning include Accounts Payable, Treasury, Procurement, and vendor communications?

Bottom Line

The story has developed beyond an April product announcement. Mythos Preview produced reported findings at scale, Project Glasswing expanded, Mythos 5 was introduced, government restrictions interrupted access, and Anthropic responded with additional safeguards and a proposed jailbreak framework.

The Alberta case study also shows how the same class of technology could help defenders examine large systems, prioritize security work, and remediate vulnerabilities much faster than before.

For Accounts Payable, the main lesson is not that every AP department needs its own cybersecurity model. The lesson is that the technology supporting invoices, vendor data, approvals, and payments is entering a faster security cycle.

AP professionals do not need to become penetration testers. They do need to protect payment authority, follow vendor-change controls, respond to security updates, and participate in continuity planning.

Security is no longer somebody else’s problem once it reaches the payment workflow.

Sources & Further Reading

Editorial Note: This article was updated on July 10, 2026, to improve the formatting and include developments reported after the original April 11, 2026 publication date.

Headshot of Robert Ruhno, Executive Director of APPG
APPG Contributor
Robert Ruhno
Executive Director, Accounts Payable Professionals Group
Accounts Payable Professionals Group logo

Practical AP reporting, controls guidance, automation coverage, and career support for the accounts payable community.

Back to top ↑

Wednesday, April 8, 2026

Accounts Payable Fraud Prevention, Modern Risks

Fraud Is No Longer Breaking Your Process, It’s Using It

If a fraudulent payment left your organization today, would you know exactly how it happened?

Published on

Accounts Payable fraud prevention concept showing invoice and cybersecurity protection

Modern AP fraud often looks like ordinary business until the payment is gone.

If a fraudulent payment left your organization today, would you know exactly how it happened?

Or would you find yourself retracing steps, digging through emails, and trying to reconstruct a process that looked perfectly normal until the money was gone?

That question came up during a recent IOFM webinar on fraud-proofing Accounts Payable, and it stuck with me. Because it gets to the heart of what’s changed.

Fraud isn’t what it used to be.

It’s not sloppy emails. It’s not obvious red flags. It’s not the “Nigerian prince” anymore.

Today’s fraud is clean. Timed well. Often AI-assisted. And most importantly, it flows through your process instead of breaking it.

Data Snapshot

Recent fraud data helps explain why this issue feels so urgent right now.

  • AFP reported that 79% of organizations experienced attempted or actual payments fraud in 2024.
  • AFP also found that 63% of respondents identified business email compromise as the top avenue for fraud attempts.
  • FBI IC3 reported 21,442 BEC complaints in 2024, with adjusted losses above $2.7 billion.
  • FinCEN has continued warning about mail theft-related check fraud, reinforcing that paper checks still carry serious risk.

The Uncomfortable Truth About AP Fraud

Here’s the reality:

Most AP teams already have controls. Policies. Procedures. Approval workflows.

And yet, fraud is still getting through.

Why?

Because those controls were built for a different era.

Today, fraudsters don’t need to hack your systems. They just need to trick your people.

  • Impersonate vendors
  • Submit fake bank account change requests
  • Intercept emails
  • Send invoices that look almost identical to real ones

And they do it at exactly the right moment.

That’s the key. Timing.

Fraud today is not random. It’s strategic.

What This Looks Like in Real Life

A payment fraud attempt does not always arrive looking suspicious.

  • A vendor email arrives with “updated remittance instructions.”
  • The logo looks right, the tone sounds normal, and the invoice amount feels believable.
  • The timing creates pressure because the payment run is approaching.
  • Someone makes the change because it fits the normal workflow.
  • The process works exactly as designed, but the money goes to the wrong account.

That is why modern AP fraud is so dangerous. It often succeeds by looking routine.

Emerging 2026 Risks

Classic fraud tactics still matter, but the next layer is becoming harder to spot.

  • AI-generated invoices can look nearly perfect.
  • Voice cloning can make an urgent callback sound legitimate.
  • Synthetic vendor identities can be built to look real before a payment request is ever made.

The point is not to panic. The point is to stop assuming that “it looks normal” is enough.

Where AP Is Most Exposed

The biggest risks in AP are not always where we think.

1. Email
Email is still the backbone of AP communication. It is also one of the least secure channels.

2. Paper Checks
Checks remain one of the largest sources of fraud losses. They can be intercepted, altered, or stolen.

3. Manual Processes
Any process that depends on someone “just catching something” introduces risk.

4. Bank Account Changes
One of the fastest-growing fraud vectors, often still verified manually.

Why This Matters Now

This is also happening while the payments environment is tightening its expectations around fraud control.

Nacha’s fraud monitoring rule changes began Phase 1 on March 20, 2026, with broader Phase 2 implementation moving into practical effect on June 22, 2026. That does not solve AP fraud by itself, but it reinforces a larger point: payment risk management is becoming more structured, more visible, and harder to treat as an afterthought.

The Shift AP Needs to Make

The biggest takeaway is this:

Fraud prevention is no longer about being more careful.

It’s about being more structured.

1. Train Continuously, Not Once

Fraud evolves constantly. Training must be ongoing, practical, and relevant.

2. Reduce Trust, Increase Verification

Every change, especially bank account updates, should be independently verified.

3. Automate Where It Matters

Automation is not just about efficiency. It strengthens control.

  • Flag unusual invoice patterns
  • Detect duplicate submissions
  • Identify abnormal payment amounts
  • Spot invoice amounts just below approval thresholds
  • Surface suspicious vendor address or account changes
  • Support stronger audit trails and cleaner approval workflows

4. Move Away from Paper

Electronic payments significantly reduce fraud exposure.

Virtual cards are especially effective because they are:

  • Single-use
  • Amount-specific
  • Vendor-specific

That does not mean every supplier will accept them. But it does mean AP leaders should be looking harder at where checks still remain and asking whether those payment types are creating avoidable exposure.

AP Fraud Pressure Test

If you want a quick gut check, start here:

  • Are vendor bank changes independently verified outside email?
  • Are paper checks limited and protected by positive pay?
  • Are unusual or duplicate invoices automatically flagged?
  • Are approval and payment functions separated?
  • Are approval thresholds reviewed for manipulation risk?
  • Are vendor master file changes restricted and logged?
  • Is fraud training recurring instead of one-time?
  • Is there a written response plan for suspected payment fraud?

If several of those answers are “no,” your AP process may be relying more on trust than structure.

Final Thought

Accounts Payable is no longer just a processing function.

It is a control function.

It sits at the intersection of cash, vendors, and execution, which makes it one of the most targeted areas in any organization.

And while external fraud gets most of the attention, strong process design also helps reduce the risk of internal manipulation, collusion, and control override.

The companies that recognize this shift will adapt.

The ones that don’t will eventually learn the hard way.

Questions for AP Leaders

Now I’d like to hear from you:

What do you believe is the single biggest fraud risk in your AP process right now?

And if a suspicious payment request landed in your inbox today, would your current process catch it, or would it let it pass through?


Headshot of Robert Ruhno, Executive Director of APPG
Robert Ruhno
Executive Director
APPG
AP Professionals logo
🟥 LinkedIn
🟧 X
🟨 Instagram

Back to top ↑

More on this topic:

NACHA Fraud Monitoring Deadline

Back to Home AP News | Controls & Risk The NACHA Deadline You Already Mis...