Berlin investigates new data leak after hackers publish stolen login credentials








The Trump Administration’s decision to punish Anthropic for its stance forbidding Claude’s use in domestic surveillance and autonomous weapons by identifying it as a supply chain risk to national security was “arbitrary and capricious,” a federal judge ruled on Thursday.
US District Court Judge Rita Lin said federal authorities had no legitimate reason to tell companies with government contracts that they couldn’t work with Anthropic.
“The undisputed record shows that the challenged actions constituted unlawful retaliation in violation of the First Amendment and that Anthropic was denied the pre-deprivation process required under the Fifth Amendment,” Lin said in her ruling, calling the designation “arbitrary and capricious.”
She stressed that the government action seemed punitive, and was not based on legal and national security risks.
The government’s words and deeds “confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model,” Lin wrote.
She pointed out, “a few days before the challenged actions began, Secretary Hegseth proposed applying the Defense Production Act to Anthropic, which would mean the company was essential to national security rather than a threat to it. Even now, the government is discussing collaboration with Anthropic on its new model, Mythos, in an array of sensitive contexts. None of that is consistent with a genuine fear that Anthropic is a saboteur [that] would poison its software to harm national security.”
The judge added that the stated government fears made no sense, noting that the usage policy applicable to Pentagon work is a purely contractual limit. “Anthropic is incapable of enforcing it technologically, and does not have direct visibility into how DoW [Department of War] uses its model,” she pointed out.
“Nothing in the Administrative Record describes, even at a high level, what technological means would give rise to the so-called ‘backdoors’ or could otherwise allow Anthropic to ‘disable’ or affect Claude during a DoW operation,” the judge wrote. “Anthropic has submitted unrebutted evidence that it lacks any technological means to access or control deployed models.”
Lawyers, consultants, and analysts who looked at the decision were confident that the case would be appealed, and that it will end up in the US Supreme Court.
Alan Webber, program VP for national security, defense, and intelligence at IDC, said that Lin’s ruling “was that the label [supply chain risk] was retaliation for Anthropic refusing to loosen safety guardrails DoD [Department of Defense, aka the Department of War] wanted lifted, dressed up in national security language. Put another way, a government customer tried to use a supply chain risk designation as leverage in a contract dispute over model behavior and application, and not because of an actual vulnerability.”
Webber said the implications for CIO strategy are concerning.
“If a government CIO is relying on a vendor’s contractual guardrails, this case says those commitments can potentially become the trigger for exactly the kind of blacklisting that risk registers are supposed to protect against,” Webber said, noting that anyone who paused Claude usage or froze a subcontract because of the DoD mandate has a legal basis to resume the initiatives. “But obviously that doesn’t mean they will, or even should, as this will be appealed.”
He added that competing AI vendors have been using the government action as a sales tool, and with this ruling, the argument that Anthropic is a designated supply chain risk ”just got weaker, which could lead to contract award disputes.”
Consultant Brian Levine, executive director of FormerGov, recommended that CIOs do what they should have always done: Evaluate all products based solely on their merits.
“CIOs should focus on using the frontier models that they believe make the most sense for their business, considering factors such as effectiveness, cost, security, safety, and confidentiality,” he said. “Anthropic and the other large frontier models each have too much market share to make retaliation for their use realistic, and the administration seems to have already moved on from this particular battle.”
Justin Greis, CEO of consulting firm Acceligence, agreed that this case has profound implications for CIOs and their AI decisions.
What the federal judge did was reject the leap from a commercial and policy disagreement to an expansive supply chain risk designation without a sufficiently grounded technical rationale or process, Greis pointed out.
“The court found that Anthropic did not have the ability to access, alter, or shut down models once deployed in the government environment, and that the government ultimately conceded Anthropic’s technology was not inherently riskier than other comparable black box AI models,” he said.
“I think that distinction matters enormously for CIOs and CISOs,” he stressed. “As AI becomes part of the operating fabric of an enterprise, ‘We don’t trust the vendor’ cannot become a substitute for a defined risk model. Organizations need to be able to articulate what the actual technical risk is, how it manifests, what controls exist, and whether the response is proportional to that risk.”
“That becomes particularly important with AI,” he added, “because people can easily conflate disagreements over model behavior, usage policies, ethics, contractual restrictions, and cybersecurity into one amorphous category called ‘AI risk.’”
Mark Rasch, a former federal prosecutor who is now general counsel at Unit221B, a threat intel and security consulting company, said he was surprised by how quickly government attorneys surrendered on this case.
“One of the things that struck me is that the government appears to have abandoned any rationale it might have had for its decision about Anthropic,” he said. The government “came back with all these reasons, but then they abandoned them all when they had to prove them.”
But, he said, the government instruction to all government contractors to also shun Anthropic was problematic.
“It’s one thing for the government to say ‘We’re not going to do business with you.’ It’s quite another thing to say ‘Nobody we do business with can do business with you either,’” Rasch said. “This says that if you are disfavored by the administration, they’re not just going to blacklist you and say they won’t do business with you. They’re going to say that nobody can do business with you.”
Rasch predicted that the legal arguments in the Supreme Court will be quite different, and will potentially sidestep the lack of evidence.
“In the Supreme Court, [the government’s] biggest argument will not be that ‘We are right that it is a supply chain risk,’ but that, ‘Whether we’re right or wrong is irrelevant. We get to make that [supply chain risk designation] decision, not the court.’”
That would mean that the Supreme Court Justices could avoid exploring whether the government made the right decision, and instead focus on whether the government has the unlimited right to decide who is a national security risk.
This article originally appeared on Computerworld.






Every decade or so, a new form of infrastructure becomes the thing that separates economies that compound from economies that stagnate. In the 20th century, it was ports, highways and power grids. Right now, it’s compute. And governments around the world are scrambling to get a piece of it — offering land, tax breaks and power guarantees to a small group of American and Chinese technology companies — without fully understanding what they’re trading away or what they’re actually competing for.
I’ve spent my career designing and building these facilities. Here’s what I see.
When a government announces it’s attracting a hyperscale data center, the press release usually mentions jobs, digital transformation and becoming a regional tech hub. What it rarely mentions is what the country is giving up and what it will need to sustain the facility for the next 20 years.
A large data center — say, 100 megawatts — needs roughly the same power as a small city. It needs that power reliably, 24 hours a day, with redundancy built in so that a grid fluctuation doesn’t take down critical systems. It needs water, often millions of gallons per month, for cooling. It needs fiber connectivity with multiple diverse routes. It needs a construction workforce that understands raised floor systems, precision cooling, high-voltage electrical distribution and fire suppression. And it needs all of this before a single server is installed.
Most developing countries don’t have this. Not yet. And the gap between “we want a data center” and “we can sustain one” is exactly where deals fall apart, projects stall or facilities get built and then underperform.
The United States has roughly 4,000 data center facilities, more than any other country by a wide margin. That number is growing faster than most of the rest of the world combined. The reasons are structural: deregulated power markets in key states, established fiber networks, deep capital markets, a legal system investors trust and decades of operational knowledge in the industry.
China is building at comparable speed but inside a closed system. Its facilities serve Chinese companies under strict data localization rules. For global capital allocators, China is largely a separate game.
The EU is growing but constrained by its own regulations. GDPR and data sovereignty laws mean European data often must stay in Europe, which is creating demand — but also creating friction. Energy costs, permitting timelines and land constraints in Western Europe are pushing investment toward Nordic countries (cheap hydropower, natural cooling) and Central and Eastern Europe (lower costs, EU membership).
Singapore, Australia and Japan are the established APAC anchors. They have the rule of law, the connectivity and the enterprise demand. But Singapore banned new data center construction outright from 2019 to 2022 over resource concerns, and even its 2025 reopening came with strict sustainability quotas that leave hundreds of megawatts of demand unmet. The pressure is redistributing.
India is the clearest breakout story. It has real enterprise demand, a growing hyperscaler presence and government policy actively supporting data center investment — including a 20-year tax holiday for foreign cloud operators announced in the 2026 budget. The challenges are grid reliability and water scarcity in key metro areas — solvable problems, but they require serious infrastructure investment alongside the facilities themselves.
Southeast Asia — Indonesia, Malaysia, Thailand, Vietnam — is attracting genuine capital. Malaysia in particular has moved fast, drawing more than $24 billion in approved data center investment and positioning Johor (just across the border from Singapore) as an overflow market. The risk is that these countries are capturing construction investment and some jobs, but the operational expertise and long-term value is still flowing out.
Sub-Saharan Africa and Latin America are earlier. There is demand — mobile internet penetration is driving real data needs — but the power infrastructure in most markets isn’t ready for hyperscale. What’s viable today is edge computing: smaller, distributed facilities closer to users that don’t require the same power density. This is where early investors are looking.
When a government announces it has attracted a hyperscale data center, the story is always the same: jobs, digital transformation, becoming a regional tech hub. What’s missing from that story is the question of who controls what.
A data center is not an economic anchor the way a factory is. A factory transfers skills, builds supplier ecosystems and creates middle-class employment at scale. A data center run by a foreign hyperscaler employs a small local facilities team, sends all operational decision-making offshore and keeps every dollar of the value it generates inside its own balance sheet. The host country gets the electricity bill and the water consumption. The technology company gets the asset.
What countries are actually competing for is not a building. It’s the right to be inside the infrastructure layer that runs the global economy for the next 30 years. That requires a completely different negotiation — one about data rights, local engineering capacity, grid co-investment and long-term operational control. Almost nobody is having that negotiation. They’re haggling over tax rates instead.
The governments that are negotiating well understand this. They’re demanding local data processing requirements, commitments to train and hire local engineers, co-investment in grid upgrades and technology transfer agreements. They’re treating compute infrastructure the way Gulf states treated oil infrastructure in the 1970s — the leverage point is during the negotiation, not after.
The governments that are not doing this will look back in 20 years and realize they subsidized someone else’s infrastructure empire.
The investment thesis in this space is not “find the next Singapore.” That window has closed. The actual opportunity is in the infrastructure gaps.
Power is the binding constraint everywhere. Companies that can solve reliable, cheap, clean power for data centers — whether through grid modernization, on-site generation or small modular nuclear reactors — are sitting on the scarcest input in the industry. This is where I’d be looking.
Second-tier markets are real. The “big four” US markets — Northern Virginia, Silicon Valley, Dallas, Chicago — are land-constrained, power-constrained and increasingly expensive. Capital is moving to the Midwest, the Southwest and internationally to markets with available power and land. The facilities being built in these markets today are the critical infrastructure of the next decade.
The countries that get the policy right — stable regulation, reliable power, fair contract enforcement — will attract disproportionate capital. The ones that don’t will keep making announcements and watching projects stall.
In the 19th century, the countries that owned the ports controlled trade. In the 20th century, the countries that controlled oil set the terms for industrial growth. Compute is next. The physical layer of AI infrastructure — the land, the power, the cooling, the fiber — is being locked up right now, mostly by a handful of private companies operating across borders with very little accountability to the countries hosting them.
For capital allocators, the opportunity is real and the window is open but not indefinitely. Power solutions, second-tier markets and policy-stable emerging economies are where the uncaptured value sits.
For governments, the window to negotiate from a position of strength is also now — before the facilities are built and the leverage is gone. Once the servers are in the ground, the terms are set.
The countries and investors who understand this in 2025 will look very smart in 2040. The ones who are still thinking about data centers as a real estate play will not.




Cybercriminals used to hacking home routers and security cameras have found another Internet-connected device to add to their botnets: your car, according to research published by Kaspersky Lab.
The post Malware Takes the Wheel: Kaspersky Finds First Car Head Unit-Specific Attack appeared first on The Security Ledger with Paul F. Roberts.
