
AI Is Supercharging Hacking While Small Hospitals and Banks Fall Behind
Small hospitals, community banks and nonprofits are poorly prepared for AI-driven cyberattacks, while the strongest defensive models remain with a handful of large technology companies.
Small hospitals, community banks and nonprofits are poorly prepared for cyberattacks that AI is making cheaper and faster, while the strongest defensive tools stay with a handful of large technology companies, The Verge reports.
Three days offline and a $3,000 bill
In March, calls began arriving at Vivian's Door, an Alabama nonprofit that supports small businesses. Partners worldwide had received emails “begging for money” that its director, Janice Malone, never sent. An outside IT team kept its systems offline for three days to close the vulnerability, and the bill reached about $3,000. Malone still cannot say whether a person or an AI system wrote the messages.
Attackers with limited skill can now lean on automated systems for what the industry calls vibe-hacking, and groups that once targeted only the most valuable victims can spread out. In August 2025, Anthropic said a single cybercrime operation used Claude Code to extort data from healthcare providers, emergency services and government bodies within one month. “Now, a single individual can conduct, with the assistance of agentic systems, what would have otherwise required a team of sophisticated actors,” said Jacob Klein, who leads Anthropic's threat intelligence team.
The strongest models stay behind closed doors
The same models are meant to help defenders, and reporting cited by The Verge found that Anthropic's Mythos flags so many software vulnerabilities that Microsoft struggles to patch them in time. But the most capable cybersecurity models, including Mythos and OpenAI's Astra, go only to a short list of large customers such as Nvidia, Google and Apple. Marius Hobbhahn of Apollo Research expects the harm far from Silicon Valley: “I expect the harm to be felt by a random Idaho hospital.”
In healthcare, it is life or death
Healthcare is at the centre of the debate. A ransomware attack forced the California provider Scripps Health to shut down key operations in May 2021, and a 2024 report ranked healthcare second in the world for attack frequency, with initial ransom demands often above $4 million. Linda Stevenson of Fisher-Titus Medical Center in Ohio says her hospital hired its first cybersecurity analyst two years ago and still has only one. “What we do is life or death,” she said.
Sean Kelly, a former emergency physician now at the security company Imprivata, says hospitals are a more attractive extortion target because care cannot continue without digital records, and an outage at one facility spreads to neighbours through diverted patients and longer waits. “All it takes is one vulnerability somewhere,” he said.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.