AIReportTechAI is supercharging hacking, and your local hospitals and banks aren’t readyNew models are helping Big Tech shore up its cyber defenses. What about everyone else?by Hayden FieldSep 28, 2026, 6:30 PM UTCShareGift Cath Virginia / The Verge | Photo: Getty ImagesAIReportTechAI is supercharging hacking, and your local hospitals and banks aren’t readyNew models are helping Big Tech shore up its cyber defenses. What about everyone else?by Hayden FieldSep 28, 2026, 6:30 PM UTCShareGiftHayden Field is The Verge’s senior AI reporter. An AI beat reporter for more than five years, her work has also appeared in CNBC, MIT Technology Review, Wired UK, and other outlets.In March, Janice Malone began getting calls about suspicious activity from her nonprofit organization, Vivian’s Door.
Vivian’s Door, headquartered in Alabama, typically provided training, resources, and community to underserved and minority-owned businesses. The work sometimes put it in close contact with these companies’ financial data, which was stored on its systems. But suddenly, concerned callers from all over the world warned they’d been getting emails “begging for money” — which she hadn’t sent.The organization’s third-party IT team pulled its systems offline for three days while they investigated the issue and plugged up the vulnerability, leaving Malone with a bill of about $3,000. She feared that she’d exposed information about the companies she was trying to help.
Even more ominously, she wasn’t completely sure if the attack was engineered by a human hacker or helped along by an AI system, or whether more were on the way.The past months have seen AI revolutionize the field of cybersecurity. OpenAI and Anthropic have disclosed that “rogue” systems escaped restrictions in their own labs and hacked everything from a small German wiki to the Australian government. Even before that, powerful models like Anthropic’s Mythos created an arms race to advance AI cybersecurity, and even lighter-weight models have allowed human bad actors to supercharge their hacking efforts.Malone isn’t sure whether AI was involved in the hack of Vivian’s Door. But amid stories of autonomous agent swarms and national security risks, she felt especially concerned.
Big AI companies were bragging about finding vulnerabilities in “every major operating system and web browser” with new models, and their big-name clients were striking deals to defend themselves with those same tools. Where did that leave her?RelatedInside the suddenly explosive world of AI safetyHumans, not rogue AI, are still the biggest cybersecurity risk to energy systems“Who knows about the next vulnerability? You only know about the one that you’ve been hit with,” Malone said, adding, “How do you protect yourself? I mean, really?”AI agents have become consistently, strikingly skilled at cybersecurity and coding, and they can be deployed at enormous scale.
Even attackers with limited knowledge of AI can engage in “vibe-hacking” with these new, automated systems, and hackers who might once have focused on only the most valuable targets can take a shotgun approach. In August 2025, Anthropic said that a sophisticated cybercrime ring used Claude Code to extort data from healthcare organizations, emergency services, religious institutions, and even government entities, all in one month.“What would have otherwise required maybe a team of sophisticated actors,” Jacob Klein, head of Anthropic’s threat intelligence team, told The Verge in an interview at the time, “now, a single individual can conduct, with the assistance of agentic systems.”In theory, AI is also supposed to safeguard cyber defenses; Anthropic’s Mythos is reportedly flagging so many vulnerabilities that Microsoft is struggling to fix them fast enough. But out of concern over potential danger, top AI labs only allow a limited list of high-profile organizations to access their most powerful cybersecurity models, like Mythos and OpenAI’s Astra. That includes companies like Nvidia, Google, and Apple, as well as other “essential infrastructure providers” and “maintainers of critical open-source software.” Even if access was more widely available, it would likely be too expensive for many smaller organizations.Now, these organizations — from healthcare clinics and municipalities to small retailers and nonprofits like Vivian’s Door — fear an increasingly lopsided power dynamic.
As Marius Hobbhahn, CEO and cofounder of Apollo Research, put it in an interview with The Verge this summer, “A single person somewhere in a basement with one of the open-source models probably could hack a hospital and demand ransom. That’s where I expect a lot of the harm to be felt. It’s not in the Bay Area… I expect the harm to be felt by a random Idaho hospital.”Small- and medium-size institutions are particularly at risk from AI agents supercharging a finite number of human hackers, says Michael Kleinman, head of US policy for the Future of Life Institute, a nonprofit focused on reducing large-scale risks of tech. And despite being small, these institutions provide vital services to their users. “Bank of America has a lot of resources to throw at this — what about community level banks?
What about savings and loans? What about credit unions? What about local hospital networks? What about local power grids?” Kleinman said. “The limiting factor used to be that there’s a finite number of malicious hackers in the world, and that’s now no longer the case.”“The limiting factor used to be that there’s a finite number of malicious hackers in the world, and that’s now no longer the case.”Malone of Vivian’s Door said that like most small businesses or nonprofits, she doesn’t have the resources for round-the-clock cybersecurity forces or IT staff hunting for unknown threats. “I just don’t know how you can really be, as a small business, totally protected on the budgets you have to do IT with,” she said.
Spending thousands of dollars on unexpected expenses to fortify the Vivian’s Door system was already tough, she said, not to mention the fact she still had to pay her staff and couldn’t do any business for days on end. If the frequency of these attacks rises, she’s ill-equipped to keep up.Craig Smith, CEO of The Cool Hardware Company, a small group of hardware stores in and around Washington, DC, says AI can be helpful for running day-to-day aspects of a small business, especially when you have limited staff. But he also acknowledged the cybersecurity risks that come from AI on the whole — not just to small companies like his, but to the larger systems he uses. Those include Microsoft tools like Outlook, Copilot, Teams, and Forms, but also things like procurement and delivery tools, which are managed by large non-tech companies.
The Cool Hardware Company uses Ace Hardware’s systems for those things, and if they were downed, it’d be very difficult for Smith to run his business.“I welcome the innovation and the changes, but with any major shift in technology, there needs to be a lot of responsibility that goes along with it,” Smith said.Mike Houston, the general manager of Takoma Park Silver Spring Co-op, a local grocer in Maryland, says he’s faced hackers firsthand as a small business — and dreads facing them again in the AI era. In recent years, he said, he’s dealt with “carting attacks”: hackers using the co-op’s online shopping platform to test thousands of stolen credit cards, racking up processing fees that he’s on the hook for. “Even if almost all of those are declined, there still can be thousands of dollars’ worth of fees in a very small amount of time,” Houston said. He’s taken the necessary precautions to try to fortify his systems against the practice, but it’s “not foolproof,” he said.The store plans to open a second location and potentially d













Leave a Reply