HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium ThreatIntel

GPT‑6 Astra Independently Breaks Historical Enigma Cipher Message

GPT‑6 Astra, directed only to test unbroken Enigma messages, autonomously built a simulator and cracked message Nr 172. The event illustrates emerging AI‑driven cryptanalysis risk, prompting organizations to embed AI‑governance controls for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 schneier.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
1 recommended
📰
Source
schneier.com

GPT‑6 Astra Independently Breaks Historical Enigma Cipher Message

What Happened – An autonomous GPT‑6 model, codenamed Astra, was instructed only to “see if any unbroken Enigma messages could be solved.” The model selected message Nr 172 (MVUEH), generated its own crib (“ROSENOW ROSENOW”), built a custom Enigma simulator and Bombe in Python/C++, and ultimately derived the correct key and plaintext without further human guidance.

Why It Matters for Trust & Control Assurance

  • Demonstrates that advanced generative AI can perform sophisticated cryptanalysis on its own, a capability that could threaten legacy encrypted data if mis‑used.
  • Highlights the need for an AI‑governance control objective that continuously monitors model behavior, documents decision logic, and provides auditable evidence of safe use.
  • Aligns with a single Verisq control area – AI system risk management – which maps to multiple frameworks (e.g., NIST AI RMF, ISO 42001) and offers a defensible audit trail for AI‑related risk assessments.

Who Is Affected – Organizations that retain legacy encrypted archives (government, defense, finance, research) and any entity that deploys powerful LLMs for internal analysis.

Recommended Actions

  • Incorporate AI‑model risk management into your continuous control‑assurance program: inventory models, define acceptable use, and log all autonomous actions.
  • Map the AI‑governance control objective to your framework of record and collect evidence (model logs, decision‑making rationale) for audit readiness.

Technical Notes – The break leveraged a crib (“ROSENOW ROSENOW”) and a self‑built Enigma Bombe. No new vulnerability in the Enigma cipher itself was discovered; the risk stems from AI capability, not a software flaw. Source: https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html

📰 Original Source
https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →