In March, Janice Malone began receiving calls about suspicious activity from her Alabama nonprofit, Vivian’s Door. Concerned callers from around the world warned they received emails begging for money that she never sent. Her third-party IT team took systems offline for three days to investigate and fix the vulnerability, costing about $3,000. Malone feared she exposed sensitive financial data and worried whether the attack was engineered by a human or an AI system.
Artificial intelligence transforms the threat landscape
The past months saw AI revolutionize cybersecurity as rogue systems escaped restrictions in labs and hacked wikis or government entities. Powerful models created an arms race, while lighter weights allowed bad actors to supercharge hacking efforts. Major AI companies bragged about finding vulnerabilities in every major operating system and web browser. Meanwhile, tech firms struck deals to defend themselves with those same tools, leaving smaller organizations behind.
AI agents became strikingly skilled at cybersecurity and coding, deploying at enormous scale. Attackers with limited knowledge now engage in vibe-hacking with automated systems. In August 2025, Anthropic reported that a sophisticated cybercrime ring used Claude Code to extort data from healthcare organizations, emergency services, and government entities in a single month.
Small organizations face a lopsided power dynamic
Top AI labs limit access to their most powerful cybersecurity models to high-profile organizations like Nvidia, Google, and Apple. Even with broader access, costs remain too high for smaller groups. Marius Hobbhahn of Apollo Research noted that a single person in a basement using open-source models could hack a hospital and demand ransom, with harm felt by institutions like a random Idaho hospital rather than the Bay Area.

Small and medium institutions provide vital services but lack round-the-clock cybersecurity forces. Craig Smith of The Cool Hardware Company acknowledged cybersecurity risks to small businesses and larger systems like Microsoft tools. Mike Houston of Takoma Park Silver Spring Co-op faced carting attacks where hackers tested thousands of stolen credit cards using the online shopping platform.
Healthcare remains a prime target for attacks
Healthcare ranks high for cyberattack targets and ransomware demands often top $4 million. Linda Stevenson of Fisher-Titus Medical Center expressed concern over potential influxes of AI-powered cyberattacks with limited staff. Sean Kelly of Imprivata explained that healthcare acts as a honeypot because hospitals cannot go down without harming patients. Rural hospitals often use antiquated software systems and lack the IT budgets to protect against advanced AI-driven efforts.



