RSS Amplifier

The AI Cookbook with Malcolm Werchota · Oct 12, 2025

The Austrian AI Security Disaster: The Fallout (Part 3 of 3)

0
Sign in to vote or save

Malcolm Werchota · The AI Cookbook with Malcolm Werchota

Over the past two days, we’ve followed Thomas’s discovery of massive security holes in LocalMind, an Austrian AI platform that promised “local and secure” data processing. Yesterday, he uncovered that the entire system was “vibe coded”—built using AI-generated code that nobody fully understood. Today: Thomas blows the whistle, the company collapses, and we extract the critical lessons every business needs to learn from this disaster. Massive credit to Günter Born from BornCity for the incredible technical reporting on this.

The Whistleblower Strikes

Thomas sends an anonymous email to each and every single LocalMind customer that he can identify. Urgent, your data has been exposed. And he explains it in the email.

And he says, look here, LocalMind promised you local and secure AI, but it’s not secure. They generated the entire infrastructure with AI vibe coding. They have a lot of security gaps.

And by the way, this hole has been open for seven months. And he attaches the report. Now he takes on a further step.

Now he acts like an imaginative investigative tech journalist from Der Spiegel. He sends it to the Austrian data protection authority, to the German federal office for information security. And by Sunday afternoon, a few hours later, LocalMind’s entire infrastructure is offline.

And Monday morning, it explodes. So German tech blogs explode. Security fiasco at an Austrian AI provider.

Marcus Wakes Up to a Nightmare

And remember Marcus Reinhardt, our tax advisor in Vienna? He opens his email. 127 unread messages from panicking clients. His partner walks in and says, Oh my God, Marcus, what the fuck did we do? But the scope becomes clearer over the next 48 hours because organisations that are affected now start coming out.

For example, the Stadt Kiel and other German municipalities, multiple banks, not one bank, multiple banks, more tax advisors and medical facilities. Now, the problem that they all have is they have a few things. And the GDPR, each and every single one of these organisations faces potential fines of, let’s say, up to 4% of the entire global revenue.

Not because they were hacked, because they trusted the wrong vendor. And LocalMind issues a statement. They admit to the breach, but they claim that the core platform was not compromised.

Now, Thomas is pissed off. He says, this is unacceptable because they quickly reacted. And LocalMind said, look, we are going to migrate your customer data.

Don’t worry about it. We will rebuild a fresh, secure infrastructure. And by the way, we will also implement proper security audits.

The Final Proof

Now, Thomas is pissed off because a few days later, people still believe LocalMind. So you know what he does? He demonstrates again that LocalMind is lying. He goes back into their system and he edits their own security status page.

And he adds corrections to their official statements. Three days later, Thomas still has access. And then the entire company pulls the plug.

Everything goes down. Try to access LocalMind’s website today. Website is offline.

Status page is offline. Customer instances are offline. And what happens to the customers and their data? They paid a lot of money, but they are worried because their data is still over there.

And they’re not getting any answers. Now, when you look a bit at security experts, what are they saying on this? They are a bit saying that obviously this is new because vibe coding is new. And now we have for the first time, a relatively large, secure platform that has been vibe coded.

So the breach is not only a textbook example of what you should not do in IT security, but you know what they’re saying? Well, it’s their own fault. They left the front door open and all the keys on the table. Another German expert on a German forum writes the following.

He says, look here, if they were serious, they should have shut that down immediately and said, look here, we will redeploy clean servers, bear with us. But what did they do? They just stayed online. This is really, really wild.

What This Means For You

So what do I think about this entire thing? Let’s come back to Marcus. Marcus, the tax advisor in the seventh district. You know, we advise tax advisors and you know what they will say? Very similar to Marcus.

I want to run AI locally. I don’t trust Microsoft. And I’m thinking, but do you understand that Microsoft spends billions in cybersecurity? Microsoft employs an army of security engineers and unlike the company LocalMind that still hasn’t done an audit, they are undergoing continuous audits.

If there was such a breach of Microsoft Copilot, I mean, probably the company could close. I’ll tell you why. Because unlike LocalMind that is going to close, in the US you would have congressional hearings.

You would have class action lawsuits of billions of dollars and massive regulatory fines. This will not happen to LocalMind. LocalMind is an Austrian company.

They will get the slap on the back and it’s like, please don’t do that. And probably they will open LocalMind Part 2 in 6 to 12 months. So geography is not security.

Just because you say, I want my data locally in Austria or in Switzerland or in Liechtenstein, it does not mean that your data is local and secure.

How to Actually Evaluate AI Providers

And if we now continue looking at what actually happened, if you want to now go and evaluate an AI provider, start with the basics. Say, look here, wonderful, we want to use you.

Could we please have your third-party security audit reports? If it’s a serious company, they would have not spent a thousand, they would have not spent 10,000, they would have spent 100,000 Euro on such a security audit report. Ask for it. And if they don’t have it, walk away.

Ask for certification that matters. SOC 2 Type 2, we made an entire episode about it. GDPR compliance documentation, ask for it.

And then, because they’re hosting all your data, have your technical team talk to their technical team. Okay, how are my credentials stored? How is your incident response procedure? If they can’t answer these details, please walk away. Now let’s talk about what actually happened and what you should do.

Well, first of all, I’m a very, very strong believer of cloud-integrated AI. Microsoft Copilot or Google Workspace is probably still today one of the safest ways to use AI. Again, why? They have the continuous audits, they have strong security updates, etc.

And they have a strong track record not since six months or nine months, like LocalMind, but for decades. Now, the next one is, if you really don’t want to work with them, then use a cloud AI platform, whatever, AWS Bedrock, OpenAI Azure, Google Vertex AI, etc. Why? Because in this case, what you can do is you can still use kind of the big models, but you can customise the cloud security.

And if you truly, truly want self-hosted open source, then probably do it at home. I mean, in your office, but then you’re responsible for all the security. And that’s crazy.

Because remember, you are responsible not only for the physical security, that it’s not just a door that anybody can break into, but you’re responsible for all the patch updates, you’re responsible for the GPU infrastructure, you’re responsible for everything that no data leaves your infrastructure.

The Real Lesson

And that, my friends, is the key insight from the LocalMind disaster. If you think local and secure is what you need, this is pure marketing bullshit.

Okay? It’s very, very difficult. And just because you run AI on-prem does not make it secure. LocalMind was local.

Yeah, it was local. It was hosted here in Austria, actually two hours from where I live. But it was the opposite of secure.

But Microsoft Copilot, they process data in the cloud, and they have an actual AI security architecture. It’s January 2026. And Marcus Reinhardt is now sitting in his office in Vienna.

And he’s probably using Microsoft Copilot to summarise client tax documentation. He does not like sending his data to Microsoft, but he probably sleeps better knowing that it’s processed by a bigger company. Unfortunately, he had to pay 47,000 Euro in incident response costs.

And he maybe, probably avoided GDPR fines. Why? Because he could probably prove that they conducted a reasonable vendor due diligence before they chose it. And Thomas, the detective who has uncovered everything, is probably still anonymous.

Until today, he still hasn’t revealed his identity. It’s a smart move, if you think about it. But these seven months where the system was open, there’s probably evidence of suspicious access from IP addresses in Eastern Europe, in China, maybe in North Korea.

But if Thomas hadn’t blown the whistle, it would have continued. And LocalMind, probably, like we discussed, they’re rebuilding, under a new entity, new people. And to be honest, they might have even survived it.

Moving Forward

And the real lesson for today’s story is, guys, the AI revolution is real. Things are going to keep moving very fast. And things are also going to break.

Not only social media apps are going to break. Larger IT and AI infrastructure systems are going to break.

And these might handle your future prosecution files, medical records, and financial data.

So yeah, there you go. Malcolm out.

No posts

Read the original on malcolmwerchota.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.