Hackers use Anthropic Claude Code to extort small businesses
As advanced AI models like Anthropic's Claude Code lower the barrier for sophisticated cyberattacks, smaller organizations face a growing defense gap compared to well-funded tech giants.

In August 2025, Anthropic revealed that a sophisticated cybercrime ring utilized its Claude Code tool to extort data from healthcare organizations, emergency services, and government entities in a single month. While advanced AI models like Anthropic's Mythos and OpenAI's Astra are helping major tech firms like Nvidia, Google, and Apple fortify their systems, smaller institutions are being left behind. These smaller entities, ranging from local hospitals to small businesses, lack the budgets and specialized IT staff required to defend against automated, agentic cyberattacks.
The impact of this lopsided dynamic is already being felt across various sectors. In Alabama, the nonprofit Vivian’s Door faced a $3,000 IT bill after taking its systems offline for three days to address a suspected breach. Meanwhile, the healthcare sector remains a prime target; a May 2021 ransomware attack on Scripps Health disrupted critical operations, and industry reports show that initial ransom demands in healthcare now frequently exceed $4 million. Even smaller entities like the Takoma Park Silver Spring Co-op in Maryland have faced costly incidents, including what general manager Mike Houston described as "carting attacks" where hackers test thousands of stolen credit cards.
For cybersecurity practitioners at smaller organizations, this shift fundamentally changes the threat landscape. Historically, the primary constraint on cybercrime was the limited number of highly skilled human hackers. Now, AI agents allow a single bad actor to launch automated, large-scale campaigns. Practitioners at institutions like Ohio's Fisher-Titus Medical Center—which hired its first cybersecurity analyst just two years ago—must secure complex environments with minimal resources. To survive, security teams at mid-sized and small organizations must pivot from reactive patching to implementing strict access controls and robust third-party monitoring, even as they operate on a fraction of the cybersecurity budgets enjoyed by Big Tech.
This is our own summary of reporting by The Verge AI



