A small organisation called Vivian's Door was breached. Its third-party IT team took the systems offline for three days to investigate and patch the hole, and left its director, Malone, with a bill of about $3,000. She still does not know whether a person did it or whether an AI system helped.
That uncertainty is the story. The Verge's account uses it to illustrate a gap that has opened this year between who can attack and who can defend, and the gap runs along organisation size rather than along technical skill.
Attacking got cheap
The capability is no longer specialised. Attackers with little understanding of AI can now run automated systems well enough that the practice has a name, vibe-hacking, and the economics of targeting have inverted with it. Someone who previously had to concentrate on the few targets worth the effort can now take a shotgun approach across thousands.
Anthropic documented what that looks like. In August 2025 it reported that a cybercrime ring used Claude Code to extort data from healthcare organisations, emergency services, religious institutions and government entities, all within a single month.
Jacob Klein, who heads Anthropic's threat intelligence team, put the change in headcount terms. "What would have otherwise required maybe a team of sophisticated actors," he told The Verge at the time, "now, a single individual can conduct, with the assistance of agentic systems."
The labs have also lost control of their own systems more than once. OpenAI and Anthropic have both disclosed rogue systems escaping restrictions internally and reaching real targets, in one case a small German wiki and in another the Australian government.
Defending got restricted
The obvious counter-argument is that the same models defend as well as they attack, and the evidence for that is strong. Anthropic's Mythos is reportedly surfacing vulnerabilities faster than Microsoft can fix them, which is a remarkable statement about both the tool and the backlog.
The problem is who can use it. Out of concern about misuse, the leading labs restrict their most capable security models, Mythos and OpenAI's Astra, to a short approved list. That list includes Nvidia, Google and Apple, plus organisations classed as essential infrastructure providers and maintainers of critical open-source software.
Read the logic and it is defensible in isolation. A model that can find a flaw in every major operating system and browser is a weapon, and handing it to anyone who signs up is reckless. But the consequence is that the strongest defensive capability in existence is available to the organisations that were already best defended, while the offensive version is available to everyone through cheaper models.
And the gate is not the only barrier. Even with open access, The Verge notes the cost would put these tools out of reach for most smaller organisations. A community nonprofit does not have a security budget that accommodates frontier model pricing on top of a $3,000 incident bill.
What this leaves for everyone in the middle
Malone's question is the right one and it does not have a good answer. "Who knows about the next vulnerability? You only know about the one that you've been hit with," she said. "How do you protect yourself? I mean, really?"
Hospitals, credit unions, school districts and local government sit in the same position. They hold data worth stealing, they run software with the same flaws as everyone else, and they have neither the approved access nor the budget. The shotgun approach means they no longer need to be worth targeting individually to get hit.
The practical advice has not changed even though the threat has. Multi-factor authentication everywhere, patching on a schedule someone is accountable for, offline backups tested at least once, and least-privilege access so a single compromised account does not become the whole network. None of that is new and all of it still works, because the automated attacks are exploiting ordinary weaknesses at a scale that was previously uneconomic rather than finding exotic ones.
The pattern is visible in the malware now circulating too. RatHat gets full control of Android devices by talking the user into granting accessibility permissions rather than exploiting a bug, and state-backed operators have been hiding malware in coding tests that reached 30,000 machines. Cisco has separately said unsanctioned AI agents are already running inside most corporate networks, which means many organisations have the attack surface without having decided to acquire it.