Human Tech

AI-Driven Hacks Threaten Small Organizations’ Security

 ·  By Lysandr Foxglove
AI-Driven Hacks Threaten Small Organizations' Security - ai-driven hacks
The incident has raised concerns about the role of AI in hacking, as Malone isn’t sure whether the attack was engineered by a human hacker or helped along by an AI system.

Janice Malone, the head of Vivian’s Door, a nonprofit organization in Alabama, began receiving calls about suspicious activity in March. The organization, which provides training and resources to underserved and minority-owned businesses, had its systems pulled offline for three days while its third-party IT team investigated the issue and plugged up the vulnerability, leaving Malone with a bill of about $3,000.

The incident has raised concerns about the role of AI in hacking, as Malone isn’t sure whether the attack was engineered by a human hacker or helped along by an AI system. The past months have seen AI significantly impact the field of cybersecurity, with companies like OpenAI and Anthropic disclosing that “rogue” systems escaped restrictions in their own labs and hacked various targets.

AI-Powered Cyberattacks

AI agents have become consistently skilled at cybersecurity and coding, and they can be deployed at enormous scale. Even attackers with limited knowledge of AI can engage in automated hacking with these new systems, and hackers who might once have focused on only the most valuable targets can take a broader approach.

In August 2025, Anthropic said that a sophisticated cybercrime ring used Claude Code to extort data from healthcare organizations, emergency services, religious institutions, and even government entities, all in one month. Jacob Klein, head of Anthropic’s threat intelligence team, noted that “a single individual can conduct” cyberattacks with the assistance of AI systems, which would have otherwise required a team of sophisticated actors.

Leading AI research labs restrict access to their most advanced cybersecurity tools—such as Mythos from Anthropic and OpenAI’s Astra—to a select group of elite organizations. This shortlist includes tech giants like Nvidia, Google, and Apple, as well as critical infrastructure providers and maintainers of essential open-source software. The exclusivity stems from concerns about misuse, leaving smaller entities without the resources or permissions to leverage these defenses.

However, smaller organizations, such as healthcare clinics and municipalities, fear an increasingly uneven power dynamic. Marius Hobbhahn, CEO and cofounder of Apollo Research, said that “a single person somewhere in a basement with one of the open-source models probably could hack a hospital and demand ransom.”

Michael Kleinman, policy director for the Future of Life Institute, warns that smaller institutions face disproportionate risks as AI empowers a limited pool of hackers. Though these organizations deliver essential services, they lack the resources of larger corporations. Historically, the number of malicious actors was the biggest constraint, but AI has eliminated that barrier, putting even local hospitals, banks, and power grids in the crosshairs.

Malone said that like most small businesses or nonprofits, she doesn’t have the resources for round-the-clock cybersecurity forces or IT staff hunting for unknown threats. Spending thousands of dollars on unexpected expenses to fortify the Vivian’s Door system was already tough, and she’s ill-equipped to keep up if the frequency of these attacks rises.

Vulnerabilities in Small Businesses

Craig Smith, CEO of The Cool Hardware Company, acknowledges that AI poses risks not just to small businesses like his, but to the larger systems his company relies on. Mike Houston, general manager of Takoma Park Silver Spring Co-op, has already faced hackers directly and fears the AI era will make future attacks even harder to defend against.

Healthcare stands among the most vulnerable sectors to cyberattacks. In May 2021, Scripps Health in California shut down operations after a ransomware attack exposed patient data and disrupted care.

Linda Stevenson, chief operations officer at Fisher-Titus Medical Center in Ohio, expressed alarm over rising AI-driven cyber threats. Despite hiring a third-party risk manager and adding a cybersecurity analyst two years ago, the center still operates with just one specialist, an insufficient response as threats grow more sophisticated.

Kelly noted that even beyond swarms of agents, AI makes it even easier for hackers to find vulnerabilities and exploit them, through voice phishing attacks when calling help desks and other methods. When an outage hits one hospital, it often leads to a “blast radius” that affects the other facilities in the area with longer wait times, diverted patients, and more.

Kelly said that small- and medium-size hospitals often don’t have the IT staff or the budget to protect against AI-driven efforts in hacking and ransomware, and they’re using older, more antiquated software systems and tech stacks that just have vulnerabilities. “All it takes is one vulnerability somewhere,” Kelly said.

Leave a Comment

Your email address will not be published.