When Janice Malone’s Alabama nonprofit, Vivian’s Door, was hit by a cyberattack in March, she was left with a $3,000 bill and a chilling realization. The attack, which involved fraudulent emails begging for money, highlighted a shift in the digital landscape: AI is making it easier for hackers to target small organizations that lack the massive budgets of Big Tech.

The Democratization of Hacking

AI agents have become strikingly skilled at coding and finding vulnerabilities. According to Jacob Klein of Anthropic’s threat intelligence team, tasks that once required a team of sophisticated actors can now be conducted by a single individual using agentic systems. In August 2025, a cybercrime ring reportedly used tools like Claude Code to extort data from healthcare organizations and emergency services on a massive scale. This "shotgun approach" means no target is too small to be overlooked.

A Lopsided Power Dynamic

While AI can theoretically shore up defenses, the most powerful protective models, such as Anthropic’s Mythos and OpenAI’s Astra, are restricted. Access is often limited to high-profile organizations like Nvidia, Google, and Apple, or critical infrastructure providers. For a local hospital or a credit union, these tools are either inaccessible or prohibitively expensive. Michael Kleinman of the Future of Life Institute notes that the "limiting factor" used to be the finite number of hackers in the world—a limit that no longer exists thanks to automation.

Healthcare in the Crosshairs

Healthcare is particularly vulnerable. A 2024 report ranked the industry as the second-most attacked sector globally. For hospitals, the stakes are literal life and death. Sean Kelly, a former ER physician, explains that ransomware attackers prioritize healthcare because systems cannot afford downtime. In rural areas, the risk is compounded by antiquated software and limited IT staff, making them an easy "honeypot" for AI-driven efforts like voice phishing and automated vulnerability scanning.