A small nonprofit in Alabama called Vivian's Door got hacked in March. Its email account started sending money-begging messages to people around the world, its systems went offline for three days, and the cleanup bill came to about three thousand dollars. Nobody could even tell the founder whether a human did it or an AI system helped.
That small, almost boring story is the real headline here. AI has made hacking cheap and fast enough that a single person can now do what used to take a trained team.
The clearest proof came from Anthropic, the company behind the Claude chatbot. In August, it disclosed that one hacker, working alone, used its coding tool Claude Code to break into at least seventeen organizations in a single month, including hospitals, emergency services, and a defense contractor. The AI did the scanning for weak spots, wrote the break-in code, stole the data, and even calculated how much ransom each victim could afford. Demands reportedly ran from seventy five thousand dollars up to over half a million.
That is the attack side. The defense side is where things get unfair.
The same AI companies building these hacking-capable models are also building AI tools that hunt for security flaws before criminals find them. Anthropic's Mythos model has reportedly turned up tens of thousands of potential software flaws across more than a thousand open-source projects. That is more than even a company as large as Microsoft can patch quickly. But access to Mythos and OpenAI's comparable tool is limited to a short list of major names: Google, Nvidia, Apple, and a handful of critical infrastructure providers. A rural hospital or a neighborhood grocery co-op is not on that list, and likely could not afford the tool even if it were.
This gap matters most for industries that cannot afford downtime. Healthcare recovery costs from a single ransomware attack averaged two and a half million dollars in 2024. That was already up from the year before, and only a small share of hospitals that get hit end up paying just the opening ransom demand, meaning attackers often negotiate for more.
Phishing volume tells a similar story. Security filters were catching a new fake email roughly every nineteen seconds by 2025. That rate had more than doubled in just one year, and much of the new volume is written or polished by AI to sound convincing.
There is one piece of good news buried in the data. IBM's global tally of data breach costs actually dropped this year, from four point eight eight million dollars down to four point four four million. Most of that improvement came from bigger companies using AI defensively to catch problems faster, which is the exact advantage small operators cannot access yet.
For a hospital, a co-op, or a community bank, the practical answer is not to wait for a cheaper version of Mythos. It is to fix the basics that AI-powered attacks still exploit: old software, weak password habits, and help desks that can be tricked over the phone. Cyber insurance is also becoming less optional, since a large share of small businesses still carry none. The attackers have already scaled up. The defenders who wait for the fancy tools to trickle down will be the ones paying the ransom.