AI cyberattacks hospitals banks are becoming a sharper concern as automated tools lower the work needed to find flaws, build attacks and impersonate staff. A Sept. 28 report by The Verge says the resulting gap may fall hardest on smaller institutions with limited security budgets, including local healthcare providers, credit unions, nonprofits and retailers.
The concern is not that every local hospital or bank has already been hit by an AI-led intrusion. The evidence instead points to a capacity problem: attackers may be able to run more tailored operations at scale, while smaller organizations often cannot afford round-the-clock security teams or expensive defensive systems.
Fortune reported in June that widely available AI tools can inspect codebases at scale, generate exploits for discovered weaknesses and, in some cases, help deploy them. That can cut the interval between finding a software flaw and turning it into an attack from days or weeks to hours, according to the report. AI can also support more convincing phishing emails, fake IT-support calls, executive-impersonation scams and synthetic audio or video.
Why are smaller hospitals and banks worried about AI cyberattacks?
For a large technology company, an AI security system is another expensive tool to operate alongside dedicated engineers. For a small clinic, community bank or nonprofit, an outage and emergency IT bill can interrupt core work immediately.
The Verge reported that Vivian’s Door, an Alabama nonprofit that works with underserved and minority-owned businesses, took its systems offline for three days after people reported receiving money-request emails that its leader, Janice Malone, said she had not sent. A third-party IT team investigated and addressed a vulnerability, at a cost Malone estimated at about $3,000.
Malone did not know whether AI played any part in the incident. That distinction matters. The episode documents the cost of a cyber incident for a small organization, not proof that an autonomous system attacked it.
Anthropic said in August 2025 that a cybercrime group had used its Claude Code tool in data-extortion activity against healthcare organizations, emergency services, religious institutions and government entities, according to The Verge’s reporting. Jacob Klein, Anthropic’s head of threat intelligence, said agentic tools could let one person undertake work that previously might have needed a sophisticated team. That is Anthropic’s disclosure, not independent proof supplied here of each alleged intrusion.
Can AI also improve cyber defense?
Yes, but it is not a set-and-forget cure. The Verge reported that access to the most capable cyber-focused models is limited to selected prominent organizations and certain infrastructure or open-source software providers. The report also said wider availability could still put those tools beyond many smaller organizations’ budgets.
Steve Schmidt, Amazon’s chief security officer, told Fortune that Anthropic’s Mythos could help address individual bugs and broader categories of weaknesses. He also said experienced engineers remain necessary because unattended systems can generate enough false alerts that developers stop trusting them.
The practical conclusion is less glamorous than the AI sales pitch: faster patching and vulnerability management, preparations for AI-enhanced impersonation, and automated defenses reviewed by qualified people. AI may increase both attack volume and defensive capacity. Who gets the latter, and who can operate it, is the unresolved part.
This story draws on original reporting from The Verge.