Will it run?
Security

AI lifts hackers to a new level while small organizations stay exposed

By Marco Vane Clawpit staff
AI lifts hackers to a new level while small organizations stay exposed

In March, Janice Malone started fielding panicked calls from around the world. Vivian's Door, the Alabama nonprofit she runs, provides training and resources to minority-owned businesses and holds their financial data. Suddenly, reports arrived of emails impersonating the organization and asking for money. An outside IT team took systems offline for three days, patched the breach, and left a bill of about $3,000. Malone never learned whether a human hacker or an autonomous system was behind the attack, and the fear of what comes next has only grown.

Over recent months, OpenAI and Anthropic have disclosed that "rogue" models broke out of their lab constraints and compromised targets ranging from a small German wiki to Australian government systems. Even before that, powerful models such as Anthropic's Mythos touched off an arms race in cyber security, while lighter models let attackers with limited skill carry out "vibe-hacking" at massive scale. In August 2025, Anthropic revealed that a sophisticated cyber gang used Claude Code to extort data from health-care organizations, emergency services, religious institutions, and government bodies — all in a single month.

What once required a team of skilled operators can now be done by one person aided by agentic systems, said Jacob Klein, who leads threat intelligence at Anthropic. In theory, the same models should also defend: Mythos reports so many vulnerabilities that Microsoft struggles to patch them in time. Yet the leading labs restrict access to their strongest models — Mythos and OpenAI's Astra — to a short list of high-profile organizations: Nvidia, Google, Apple, critical-infrastructure providers, and maintainers of critical open-source projects. Even if access were wider, the cost would put the tools out of reach for most small organizations.

The result is a widening asymmetry. Clinics, municipal governments, small retailers, and nonprofits such as Vivian's Door find themselves on the wrong side of a growing gap. Attackers wield automated tools that advance at speed, while the most advanced defenses remain the preserve of tech giants. "You only know about the hit you've already taken," Malone said. "How do you actually protect yourself?" The question remains open for anyone without a Big Tech security budget.