Lifestyle

AI is making hacking easier, and The Verge says local hospitals and banks aren't ready

The Verge reports that the most powerful AI security tools are mostly available to large companies, while small hospitals, banks and nonprofits may struggle against AI-assisted attacks. Here is what the report and Anthropic's own announcement say, and what it means for ordinary people.

About 6 min read

AI is making hacking easier, and The Verge says local hospitals and banks aren't ready
Image: Mokaair (Original editorial artwork)

What happened

Hayden Field, senior AI reporter at The Verge, published a report on September 28, 2026, saying that AI is intensifying hacking attacks and that local hospitals and banks aren't ready. The report cites the Alabama nonprofit Vivian's Door as an example: according to the report, its head, Janice Malone, began receiving calls about suspicious activity in March. The organization's outside IT team took its systems offline for three days to investigate and fix the security weakness, for which she paid about $3,000. The report also notes that Malone is unsure whether AI was involved in the attack.

According to The Verge, Anthropic said in August 2025 that a cybercrime group had used Claude Code, Anthropic's AI coding tool, over the course of one month to extort data from healthcare organizations, emergency services, religious institutions and government bodies.

AI is making hacking easier, and The Verge says local hospitals and banks aren't ready
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

The gap between large and small organizations

According to The Verge, top AI labs allow only a limited set of well-known organizations to use their most powerful security models, such as Anthropic's Mythos and OpenAI's Astra, with a list that includes Nvidia, Google and Apple. These models can search software for vulnerabilities, meaning security flaws that attackers could exploit. The report adds that even if access were opened up, pricing could put them out of reach for many small organizations. It also mentions reports that Mythos flagged so many vulnerabilities that Microsoft struggled to patch (fix) them in time.

As quoted by The Verge, Michael Kleinman, head of US policy at the Future of Life Institute, believes small and mid-sized organizations are especially vulnerable to AI agents (AI systems that can carry out tasks on their own) amplifying human hackers' capabilities. He says the past constraint of a limited number of malicious hackers no longer holds. Marius Hobbhahn, CEO of Apollo Research, told The Verge that he expects the harm to fall on institutions such as local hospitals rather than the Bay Area.

Compiled from Anthropic's announcement and The Verge's report; each column reflects its own source's statements
AspectAnthropic's official statementsSmall organizations' situation in The Verge's report
Access to advanced security modelsProject Glasswing expanded to about 150 new organizations, each required to meet security requirementsThe most powerful models are open only to a limited set of well-known organizations; small organizations may be unable to afford them
CoverageNew organizations span more than 15 countries, including electricity, water, healthcare, communications and hardwareInterviewees include a nonprofit, a hardware store and a local co-op grocery
Main challengeThe bottleneck shifts to verifying, disclosing and patching large numbers of vulnerabilitiesInterviewees say they lack round-the-clock security staff and budget

How Anthropic describes Project Glasswing

Anthropic announced the expansion of Project Glasswing on June 2, 2026. The company said about 50 initial partners gained access to Claude Mythos Preview in early April and have found more than 10,000 high- or critical-severity security vulnerabilities. This round expands the collaboration to about 150 new organizations in more than 15 countries, covering industries such as electricity, water, healthcare, communications and hardware.

Anthropic also said it expects many other AI companies to have Mythos-class models (models with similar abilities to find security flaws) within 6 to 12 months, possibly released without safeguards against misuse. The company said it has launched Claude Security, which uses publicly available frontier models (its most advanced public models), such as Claude Opus 4.8, to scan code and suggest fixes. It also plans to expand its Cyber Verification Program. Anthropic acknowledged that robust safeguards sufficient to make Mythos-class capabilities generally available have not yet been developed by the company or, to its knowledge, by any other AI developer.

What it means for ordinary readers

According to The Verge, it isn't only large tech companies that are affected. Mike Houston, general manager of a co-op grocery in Maryland, said the store had faced attacks in which hackers used its online shopping platform to test stolen credit cards. Even when most transactions are declined, these can generate thousands of dollars in fees within a short time. Hardware store owner Craig Smith said his business depends on Microsoft tools and Ace Hardware's systems, and would be hard to run if they went down.

  • Watch for unusual requests for help or money transfers sent in the name of organizations or people you know, and confirm them through another channel first.
  • Check your bank and credit card transactions regularly, and contact your card issuer promptly if you find unfamiliar charges.
  • If you run a small organization, ask your current IT provider about its arrangements for patching, updates and backups.

Frequently asked questions

Was the attack on Vivian's Door definitely caused by AI?

No, that is uncertain. According to The Verge, its head, Janice Malone, is herself unsure whether AI was involved in the attack.

Can small organizations use models like Mythos?

According to The Verge, the most powerful security models are currently open only to a limited set of well-known organizations, and even if opened up they may be too expensive. Anthropic says it plans to expand its Cyber Verification Program, but the safeguards needed for general availability have not yet been developed.

How many organizations has Project Glasswing expanded to?

Anthropic says it has expanded to about 150 new organizations in more than 15 countries, each of which must first meet its security requirements.

Why does Anthropic think time is short?

Anthropic says it expects many other AI companies to have Mythos-class models within 6 to 12 months, possibly released without safeguards against misuse.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle