Lifestyle
AI is making hacking easier, and The Verge says local hospitals and banks aren't ready
The Verge reports that the most powerful AI security tools are mostly available to large companies, while small hospitals, banks and nonprofits may struggle against AI-assisted attacks. Here is what the report and Anthropic's own announcement say, and what it means for ordinary people.
About 6 min read

What happened
Hayden Field, senior AI reporter at The Verge, published a report on September 28, 2026, saying that AI is intensifying hacking attacks and that local hospitals and banks aren't ready. The report cites the Alabama nonprofit Vivian's Door as an example: according to the report, its head, Janice Malone, began receiving calls about suspicious activity in March. The organization's outside IT team took its systems offline for three days to investigate and fix the security weakness, for which she paid about $3,000. The report also notes that Malone is unsure whether AI was involved in the attack.
According to The Verge, Anthropic said in August 2025 that a cybercrime group had used Claude Code, Anthropic's AI coding tool, over the course of one month to extort data from healthcare organizations, emergency services, religious institutions and government bodies.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
The gap between large and small organizations
According to The Verge, top AI labs allow only a limited set of well-known organizations to use their most powerful security models, such as Anthropic's Mythos and OpenAI's Astra, with a list that includes Nvidia, Google and Apple. These models can search software for vulnerabilities, meaning security flaws that attackers could exploit. The report adds that even if access were opened up, pricing could put them out of reach for many small organizations. It also mentions reports that Mythos flagged so many vulnerabilities that Microsoft struggled to patch (fix) them in time.
As quoted by The Verge, Michael Kleinman, head of US policy at the Future of Life Institute, believes small and mid-sized organizations are especially vulnerable to AI agents (AI systems that can carry out tasks on their own) amplifying human hackers' capabilities. He says the past constraint of a limited number of malicious hackers no longer holds. Marius Hobbhahn, CEO of Apollo Research, told The Verge that he expects the harm to fall on institutions such as local hospitals rather than the Bay Area.
| Aspect | Anthropic's official statements | Small organizations' situation in The Verge's report |
|---|---|---|
| Access to advanced security models | Project Glasswing expanded to about 150 new organizations, each required to meet security requirements | The most powerful models are open only to a limited set of well-known organizations; small organizations may be unable to afford them |
| Coverage | New organizations span more than 15 countries, including electricity, water, healthcare, communications and hardware | Interviewees include a nonprofit, a hardware store and a local co-op grocery |
| Main challenge | The bottleneck shifts to verifying, disclosing and patching large numbers of vulnerabilities | Interviewees say they lack round-the-clock security staff and budget |
How Anthropic describes Project Glasswing
Anthropic announced the expansion of Project Glasswing on June 2, 2026. The company said about 50 initial partners gained access to Claude Mythos Preview in early April and have found more than 10,000 high- or critical-severity security vulnerabilities. This round expands the collaboration to about 150 new organizations in more than 15 countries, covering industries such as electricity, water, healthcare, communications and hardware.
Anthropic also said it expects many other AI companies to have Mythos-class models (models with similar abilities to find security flaws) within 6 to 12 months, possibly released without safeguards against misuse. The company said it has launched Claude Security, which uses publicly available frontier models (its most advanced public models), such as Claude Opus 4.8, to scan code and suggest fixes. It also plans to expand its Cyber Verification Program. Anthropic acknowledged that robust safeguards sufficient to make Mythos-class capabilities generally available have not yet been developed by the company or, to its knowledge, by any other AI developer.
What it means for ordinary readers
According to The Verge, it isn't only large tech companies that are affected. Mike Houston, general manager of a co-op grocery in Maryland, said the store had faced attacks in which hackers used its online shopping platform to test stolen credit cards. Even when most transactions are declined, these can generate thousands of dollars in fees within a short time. Hardware store owner Craig Smith said his business depends on Microsoft tools and Ace Hardware's systems, and would be hard to run if they went down.
- Watch for unusual requests for help or money transfers sent in the name of organizations or people you know, and confirm them through another channel first.
- Check your bank and credit card transactions regularly, and contact your card issuer promptly if you find unfamiliar charges.
- If you run a small organization, ask your current IT provider about its arrangements for patching, updates and backups.
Frequently asked questions
Was the attack on Vivian's Door definitely caused by AI?
No, that is uncertain. According to The Verge, its head, Janice Malone, is herself unsure whether AI was involved in the attack.
Can small organizations use models like Mythos?
According to The Verge, the most powerful security models are currently open only to a limited set of well-known organizations, and even if opened up they may be too expensive. Anthropic says it plans to expand its Cyber Verification Program, but the safeguards needed for general availability have not yet been developed.
How many organizations has Project Glasswing expanded to?
Anthropic says it has expanded to about 150 new organizations in more than 15 countries, each of which must first meet its security requirements.
Why does Anthropic think time is short?
Anthropic says it expects many other AI companies to have Mythos-class models within 6 to 12 months, possibly released without safeguards against misuse.
Browse the latest news in this topic
Lifestyle
NVIDIA launches DGX Spark 64GB: on sale October 23 from $4,999, two units can be linked into 128GB
On October 2, 2026, NVIDIA announced a more affordable 64GB memory version of its DGX Spark personal AI computer, available from October 23 through six makers including Acer and ASUS. It is aimed mainly at developers and researchers who want to run AI models on their own machines. Below we summarize the specs NVIDIA published, its claims about linking two units, and what it means for general readers.
Lifestyle
Google Cloud Launches Spanner Queues: Putting Message Queues Inside Database Transactions to Make AI Agents More Reliable
Google Cloud has announced the general availability of Spanner queues, which make message creation part of a database transaction. The aim is to stop AI agents' "state" and "actions" from falling out of sync. This article covers Google Cloud's claims, the main features, and what it means for general readers.
Lifestyle
GPT-6.1 Sol Launches: New Sol Version in the API, Codex and ChatGPT Work, Not in Chat
OpenAI launched GPT-6.1 Sol on September 29, 2026, with the API name gpt-6.1-sol. The launch rollout covers Codex and ChatGPT Work on Plus, Pro, Business, Enterprise and Edu (Enterprise and Edu need an administrator to enable it); Free and Go are not included at launch, and it is not in Chat (checked September 2026).
Lifestyle
Claude Sonnet 5.5 Launches: Same List Price as Sonnet 5, Available in the API, on Cloud Platforms and in Claude.ai
Anthropic launched Claude Sonnet 5.5 on September 28, 2026. API list prices are the same as Sonnet 5 ($2 per million input tokens, $10 per million output tokens). It is available in Claude.ai, the API and several cloud platforms, and higher-risk cybersecurity requests fall back to Sonnet 5 (checked September 2026).
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family