The last patient care report one of my firefighters filed did not stay in our station.
It went out over the wire to a server I have never seen, in a building I could not find on a map, administered by employees of a company I have never spoken to, protected by security controls I have never been shown and would not be permitted to inspect. It sits there now alongside somebody’s cardiac history, somebody’s address, somebody’s worst night.
I do not know where that server is. Neither does the township. Neither, I would guess, does any fire officer or chief reading this.
Last week Anthropic, the company that makes the Claude artificial intelligence system, published a 154-page accounting of how criminals and foreign intelligence services have been caught using its technology to break into other people’s networks. I read the whole thing. I expected it to be about somebody else — defense contractors, banks, the kind of outfit that has a security department. Roughly forty pages in, I understood that it was about us, the fire service.
Let me be clear about what I am and am not before we go any further. I am not an information technology professional. I do not write code and I am not going to stand here and pretend to explain the mechanics of a network intrusion to you. What I can do is read a report, understand a timeline, and recognize a continuity-of-operations problem when one is described to me. That last part is the job. So that is the part I am going to talk about.
What the report actually is
It is the fourth of its kind, and it covers operations the company says it identified and shut down between December of 2025 and August of 2026. Thirty-nine cases, sorted into seven categories running from cyberattacks and surveillance to fraud and weapons development. Every case is something the company says it caught in its own records, and every account has been banned.
Two honest limits on it. The company selected these cases because they were notable, not because they were typical, so what you are reading is the leading edge rather than the average. And every figure in it is the company’s own attribution from its own logs; none of it has been independently audited. I am going to be careful throughout to say who is claiming what, because that is how we handle anything else where we only have one side’s paperwork.
What actually changed, and it isn’t the attacks
The most useful thing in the report is the part where the company steps back and says plainly that none of this is new. Stolen passwords. Unpatched equipment sitting on the internet. Phishing emails. Not one of the thirty-nine operations relied on some technique nobody had ever seen. That is worth sitting with for a second, because it means the answer is not some exotic new product.
What changed is the labor. All the grinding work that used to separate a well-funded foreign intelligence service from some kid in an apartment — mapping a target, writing the tools, sorting through mountains of stolen data — has been handed off to machines that do it in parallel, around the clock, at a speed no room full of people could match. The consequence, in the report’s own framing, is that sophistication is no longer a reliable signal of who is behind an attack. A lone individual and a state intelligence service now leave similar footprints.
Which brings me to the number that stopped me.
In one of the documented cases, an attacker went from a single stolen employee credential to full administrative control of an organization’s entire computing environment in roughly three hours. In another, a breach ran from first access to bulk theft of the company’s data in a matter of hours. In a third, an intrusion at one software vendor was used to reach into the data of roughly two hundred of that vendor’s customers.
Three hours. We think in those units. Three hours is a working structure fire through overhaul. Three hours is a two-car MVA with extrication and two transports. Three hours is most of a mutual aid response, start to finish.
Now ask yourself honestly how long it would take your department to notice that something had gone wrong with your records system, your billing platform, or your email. For most of us, the answer is not three hours. For most of us, the answer is however long it takes until somebody cannot log in on Monday morning.
That gap is the entire story.
Why this reaches a department our size
Here is the part I did not expect, and it is the reason I am writing this instead of filing it away.
A department like mine is not going to be targeted. Nobody in Moscow has heard of Stronach Township, and nobody is going to spend a morning trying to get into our building. That is not how this works anymore, and the report is unambiguous about it. The attacks that reach small organizations reach them sideways, through the vendors those organizations depend on. Break into one company that provides software to hundreds of customers, and you have reached all of them at once. One case in the report did exactly that to roughly two hundred downstream organizations. Another reached thousands.
We are a downstream customer. So is the township. So is your department, and the ambulance service, and county dispatch, and the hospital, and the school district, and your critical infrastructure like wastewater and water departments. Our patient care reporting, our billing, our email, our personnel records, our website — almost none of it runs on hardware we own or control. It runs on somebody else’s, and our security is genuinely no better than theirs, whatever ours happens to be.
There is a second finding in the report that I had not considered at all and that I would bet most chiefs have not either. Attackers have begun specifically hunting for artificial intelligence credentials inside the systems they break into — the keys that let one piece of software talk to an AI service. The report lays out why in three words: loot, compute, and cover. The keys can be resold. They let the attacker run his own operations at the victim’s expense. And every bit of that activity shows up under the victim’s name. These keys are increasingly buried inside ordinary business software without anyone in the building knowing they are there. If a vendor has quietly added an AI feature to your records system, there is now a credential somewhere in that stack that somebody wants.
What it looks like when it lands on us
This is the part where I do have standing, so let me use it.
When one of these events hits a county, it does not present as an information technology problem. It presents as an operations problem, and it runs through incident command like anything else. Dispatch goes to manual. Patient care reporting goes to paper, if anyone can find the paper and remembers the format. Billing stops, which means revenue stops, which becomes a budget problem in about sixty days. Hospital diversion decisions get made on partial information. Personnel records, including medical information on your own people, may be in somebody else’s hands and you will not know for weeks.
I have spent more than three dozen disaster deployments watching what happens when the infrastructure everybody assumed would be there simply is not. The pattern never varies much. The organizations that had thought about it beforehand degrade gracefully. The ones that had not, do not degrade — they stop. The difference is almost never money. It is almost always whether somebody sat down ahead of time and asked what we do when this specific thing is gone.
So here is the question I would put to every chief in this country, and it is not a technical question at all. If your records system, your email, and your billing platform were unavailable to you for two weeks, and you could not be certain when they would come back, could you still run your department? Could you document a run? Could you make payroll? Do you know where the paper forms are, and does anybody under forty know how to fill one out?
That is a tabletop exercise. It costs nothing but an evening. And the fact that it has never occurred to most of us to run one is, I think, the honest measure of how far behind this we are.
What a small department can actually do
Almost nothing I am about to suggest requires a budget line. Most of it requires a conversation, which is fortunate, because a budget line is not coming.
Start with the vendors, because that is where the exposure is. You are entitled to ask the companies that hold your data some direct questions, and their answers — including how long they take to give you one — will tell you most of what you need to know. Put it in writing so there is a record, and ask your clerk to keep the responses on file with the contract.
1. Where is our data physically stored, and who else has access to it?
2. Does this product use an artificial intelligence service? If so, whose credentials does it use, and where are they kept?
3. If you are breached, what is your obligation to notify us, and how fast does that clock run?
4. Has this product or your company been involved in a security incident in the last twenty-four months?
5. If your service is unavailable, how do we operate, and what do you provide to help us?
A vague answer to any of these is itself an answer, and worth noting.
Beyond that, three habits. Put two-factor authentication on everything that has a cloud login, starting with email, and do not let anyone opt out because it is inconvenient — the most sophisticated operation in the entire report got its initial foothold by abusing ordinary sign-in flows, and a stolen password by itself should never be enough to open a door. Treat hotel and conference wireless as hostile, because the report documents attackers compromising the companies that run hotel guest wireless and pushing malware onto the phones and laptops of people who connected to it, which matters to every one of us who travels for conferences and deployments. And be suspicious of any offer of cheap artificial intelligence access through some intermediary, because standing up fake discount resellers that install credential stealers on the customer’s machine is one of the criminal business models the report documents in detail.
Finally, know who you would call before you need to call them. Cyber incidents get reported to the FBI’s Internet Crime Complaint Center, and in Michigan to the State Police Cyber Command Center. Find both numbers now, put them in the same place as your other emergency contacts, and tell your officers they are there. It is a fifteen-minute job that nobody wants to be doing at two in the morning.
The part I keep coming back to
I came into this business when run reports were on carbon paper, and you pressed hard so the third copy came through. Since then I have watched the fire service absorb one outside requirement after another. Respiratory protection. NFPA compliance. HIPAA. The whole incident command apparatus. Every one of them arrived looking like somebody else’s problem, invented by people who had never pulled a hoseline, and every one became our problem whether we liked it or not. The departments that got ahead of each one did fine. The ones that waited until it was mandatory did it badly, expensively, and under pressure.
This one is different in a way I do not much like. There is no standard coming. There is no inspector, no compliance deadline, no grant cycle with our name on it. Nobody is going to make us do this, which historically has meant that most of us will not, right up until the day a neighboring county learns it in public and the rest of us read about it.
I would rather we talked about it first. That is the whole reason for this piece. I am not the person to tell you how any of it works. I am just the chief who read the report and recognized the building.
A note on sources. Everything described above comes from Anthropic’s report “Detecting and countering misuse of AI: September 2026,” published September 10, 2026, and is presented as that company’s own findings about its own platform rather than as independently established fact. The full report is free to read at anthropic.com. I have deliberately left out the technical indicator lists it contains; they are of no use to a fire department, and their presence tends to get an email flagged as spam. Where the report expressed uncertainty about a finding, I have kept that uncertainty here. If I have gotten something wrong, tell me, and I will correct it in print.
Fred R. LaPoint is Fire Chief and a licensed paramedic with the Stronach Township Fire Department in Manistee County, Michigan. He spent forty years as a professional firefighter with the City of Manistee Fire Department before retiring in 2019, and has more than fifty years in emergency services. He is a U.S. Coast Guard veteran of the Vietnam era and a disaster responder with Team Rubicon, with more than three dozen domestic and international deployments in roles including Operations Section Chief, Planning Section Chief, and Strike Team Leader. He holds ICS 100 through ICS 800 certifications. He writes Behind The Alarm and Guardians of Truth.
This article first appeared in Behind The Alarm, the newsletter of Fred R. LaPoint, Fire Chief Paramedic of the Stronach Township Fire Department, on September 12, 2026. Read the original.
