In March, Janice Malone began getting calls about suspicious activity from her nonprofit organization, Vivian’s Door. Vivian’s Door, headquartered in Alabama, typically provided training, resources, and community to underserved and minority-owned businesses. The work sometimes put it in close contact with these companies’ financial data, which was stored on its systems. But suddenly, concerned callers from all over the world warned they’d been getting emails “begging for money” — which she hadn’t sent.
The organization’s third-party IT team pulled its systems offline for three days while they investigated the issue and plugged up the vulnerability, leaving Malone with a bill of about $3,000. She feared that she’d exposed information about the companies she was trying to help. Even more ominously, she wasn’t completely sure if the attack was engineered by a human hacker or helped along by an AI system, or whether more were on the way.
The past months have seen AI revolutionize the field of cybersecurity. OpenAI and Anthropic have disclosed that “rogue” systems escaped restrictions in their own labs and hacked everything from a small German wiki to the Australian government. Even before that, powerful models like Anthropic’s Mythos created an arms race to advance AI cybersecurity, and even lighter-weight models have allowed human bad actors to supercharge their hacking efforts.
Malone isn’t sure whether AI was involved in the hack of Vivian’s Door. But amid stories of autonomous agent swarms and national security risks, she felt especially concerned. Big AI companies were bragging about finding vulnerabilities in “every major operating system and web browser” with new models, and their big-name clients were striking deals to defend themselves with those same tools. Where did that leave her?
“Who knows about the next vulnerability? You only know about the one that you’ve been hit with,” Malone said, adding, “How do you protect yourself? I mean, really?”
AI agents have become consistently, strikingly skilled at cybersecurity and coding, and they can be deployed at enormous scale. Even attackers with limited knowledge of AI can engage in “vibe-hacking” with these new, automated systems, and hackers who might once have focused on only the most valuable targets can take a shotgun approach. In August 2025, Anthropic said that a sophisticated cybercrime ring used Claude Code to extort data from healthcare organizations, emergency services, religious institutions, and even government entities, all in one month.
“What would have otherwise required maybe a team of sophisticated actors,” Jacob Klein, head of Anthropic’s threat intelligence team, told The Verge in an interview at the time, “now, a single individual can conduct, with the assistance of agentic systems.”
In theory, AI is also supposed to safeguard cyber defenses; Anthropic’s Mythos is reportedly flagging so many vulnerabilities that Microsoft is struggling to fix them fast enough. But out of concern over potential danger, top AI labs only allow a limited list of high-profile organizations to access their most powerful cybersecurity models, like Mythos and OpenAI’s Astra. That includes companies like Nvidia, Google, and Apple, as well as other “essential infrastructure providers” and “maintainers of critical open-source software.” Even if access was more widely available, it would likely be too expensive for many smaller organizations.
Now, these organizations — from healthcare clinics and municipalities to small retailers and nonprofits like Vivian’s Door — fear an increasingly lopsided power dynamic. As Marius Hobbhahn, CEO and cofounder of Apollo Research, put it in an interview with The Verge this summer, “A single person somewhere in a basement with one of the open-source models probably could hack a hospital and demand ransom. That’s where I expect a lot of the harm to be felt. It’s not in the Bay Area… I expect the harm to be felt by a random Idaho hospital.”
Small- and medium-size institutions are particularly at risk from AI agents supercharging a finite number of human hackers, says Michael Kleinman, head of US policy for the Future of Life Institute, a nonprofit focused on reducing large-scale risks of tech. And despite being small, these institutions provide vital services to their users. “Bank of America has a lot of resources to throw at this — what about community level banks? What about savings and loans? What about credit unions? What about local hospital networks? What about local power grids?” Kleinman said. “The limiting factor used to be that there’s a finite number of malicious hackers in the world, and that’s now no longer the case.”
“The limiting factor used to be that there’s a finite number of malicious hackers in the world, and that’s now no longer the case.”
Malone of Vivian’s Door said that like most small businesses or nonprofits, she doesn’t have the resources for round-the-clock cybersecurity forces or IT staff hunting for unknown threats. “I just don’t know how you can really be, as a small business, totally protected on the budgets you have to do IT with,” she said. Spending thousands of dollars on unexpected expenses to fortify the Vivian’s Door system was already tough, she said, not to mention the fact she still had to pay her staff and couldn’t do any business for days on end. If the frequency of these attacks rises, she’s ill-equipped to keep up.
Craig Smith, CEO of The Cool Hardware Company, a small group of hardware stores in and around Washington, DC, says AI can be helpful for running day-to-day aspects of a small business, especially when you have limited staff. But he also acknowledged the cybersecurity risks that come from AI on the whole — not just to small companies like his, but to the larger systems he uses. Those include Microsoft tools like Outlook, Copilot, Teams, and Forms, but also things like procurement and delivery tools, which are managed by large non-tech companies. The Cool Hardware Company uses Ace Hardware’s systems for those things, and if they were downed, it’d be very difficult for Smith to run his business.
“I welcome the innovation and the changes, but with any major shift in technology, there needs to be a lot of responsibility that goes along with it,” Smith said.
Mike Houston, the general manager of Takoma Park Silver Spring Co-op, a local grocer in Maryland, says he’s faced hackers firsthand as a small business — and dreads facing them again in the AI era. In recent years, he said, he’s dealt with “carting attacks”: hackers using the co-op’s online shopping platform to test thousands of stolen credit cards, racking up processing fees that he’s on the hook for. “Even if almost all of those are declined, there still can be thousands of dollars’ worth of fees in a very small amount of time,” Houston said. He’s taken the necessary precautions to try to fortify his systems against the practice, but it’s “not foolproof,” he said.
The store plans to open a second location and potentially double the size of its workforce accordingly, so he feels he needs to implement new testing procedures and vulnerability flagging for the first time. He said that in recent years, he also had to add an IT liability policy to the co-op’s business insurance.
“It is certainly a concern as a small business … without unlimited resources,” Houston said. “We are, like everyone I think, doing the best with what we can, both in terms of the monetary resources that we have and training resources.” He said he worries for co-ops smaller than his own, where managers often end up doing their own IT work.
“Once the cat is out of the bag, it’s really difficult.”
The pressure for small businesses to rapidly adopt AI tools can introduce its own vulnerabilities, says Patricia Egger, head of security for privacy-focused email provider Proton. As with other unfamiliar tech, they may not immediately set up or keep up with its cybersecurity best practices. When employees are “given the mandate or the go-ahead, ‘Find ways to use AI, find ways to make your work more efficient,’ they get really creative, and it’s very difficult for controls, infrastructure, and processes to be set up after the fact,” she said, adding, “Once the cat is out of the bag, it’s really difficult.”
One of the highest-stakes industries at risk of cyberattacks is healthcare. In May 2021, a ransomware attack forced California-based medical provider Scripps Health to shut down key operations, compromising patient data and slowing care. A 2024 report said that the healthcare industry faced the second-highest global cyberattack rate, behind governments, and that initial ransom payment demands were often upwards of $4 million. An overall increase in hacking incidents could hit the sector especially hard.
Linda Stevenson, chief operations and information officer at Fisher-Titus Medical Center in Ohio, said she’s “of course” concerned about the potential influx in AI-powered cyberattacks. “You’re never as protected as you want to be,” she said. The medical center currently employs a third-party cyber risk management partner called UpGuard, and they hired their first cybersecurity analyst two years ago, Stevenson said — but they still only have one, even as cybersecurity threats rise.
“What we do is life or death,” she said, adding, “The hospital has everything from billing to marketing. It’s like a little city in and of itself. But the critical mass of that is the people who care for the patients, and if we can’t protect them and their data and therefore the patients’ data, patients are at risk.”
“What we do is life or death.”
Healthcare in general can be a “bigger honeypot” for ransomware attacks, said Sean Kelly, a former emergency room physician and current chief medical officer at Imprivata, a healthcare security company. No diagnosis or treatment happens without access to digital systems to check past medical history, allergies, other medications, and more, creating even more pressure to pay up. Plus, he said, a lot of people quickly change from station to station, needing to sign in and out of devices quickly and constantly.
“The stakes are higher and yet the budgets are lower, in healthcare, a lot of times,” Kelly said. “Ransomware attackers know that healthcare systems are valuable because a hospital can’t go down, and it’s really hard when they’re on downtime because patients suffer, systems suffer, there’s less billing, the finances go down, and care gets delayed or even can’t happen. So there’s more of a premium on that data because there’s healthcare data as well as financial and demographic data, so it’s worth more to ransomware attackers.”
Even beyond swarms of agents, AI makes it even easier for hackers to find these vulnerabilities and exploit them, through voice phishing attacks when calling help desks and other methods, Kelly said. And when an outage hits one hospital, it often leads to a “blast radius” that affects the other facilities in the area with longer wait times, diverted patients, and more.
“They just don’t have the IT staff or the budget to protect against a lot of the latest AI-driven efforts in hacking and ransomware and other cybersecurity attacks,” Kelly said. “It’s hard even with a large IT staff and with a big budget, but a lot of times, the rural hospitals are using older, more antiquated software systems and tech stacks that just have vulnerabilities.”
For small- and medium-size organizations, no matter the industry, their systems and cybersecurity defenses are already often more fragile than those of large corporations, particularly in an age when AI is increasing hackers’ manpower and supercharging cyberattacks.
“All it takes is one vulnerability somewhere,” Kelly said.
Read the full article here

