Product1 publisher3 min readPublished
A $3,000 hack at an Alabama nonprofit shows who the AI labs' cyber-defense lists leave out
AI labs limit their strongest cyber-defense models, Anthropic's Mythos and OpenAI's Astra, to a short list that includes Nvidia, Google and Apple. Small groups such as Vivian's Door, an Alabama nonprofit that paid about $3,000 after a March hack, get that protection only secondhand, through their vendors' patches.
The Product Desk · Product desk

What happened
- In March, callers around the world warned Janice Malone about emails begging for money in her nonprofit's name that she had never sent.
- Malone does not know whether the attack was the work of a human hacker alone or was helped along by an AI system.
- In August 2025, Anthropic said one cybercrime ring used Claude Code to extort healthcare, emergency-service, religious and government organisations within a single month.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Small organisations receive the labs' bug-finding only as vendor patches, so their exposure depends on a patch queue Microsoft is reportedly already struggling to clear.
- exposure When one person with an agent can do a team's work, institutions that were never worth a team's effort become worth attacking in bulk.
- decision Clinics and nonprofits holding client data have to budget for detection and recovery on their own, since Mythos-class access is neither offered to them nor likely affordable.
The Verge describes the labs' pitch for the new models as finding vulnerabilities in "every major operating system and web browser" [10]. The customers are the companies that ship those systems. At the biggest of them, finding already outpaces fixing. Mythos is reportedly flagging so many vulnerabilities that Microsoft is struggling to fix them fast enough [12].
If a nonprofit in Alabama gets any of that work, it arrives as software updates from vendors working through the same backlog. What the small user in this story actually did was answer the phone. Vivian's Door relied on a third-party IT team [4], and the first warning came from people who had received begging emails in its name [3]. The bill of about $3,000 for three days offline works out to roughly $1,000 a day [1]. "Who knows about the next vulnerability? You only know about the one that you've been hit with," Malone said [7].
Attackers have no list to get onto. According to The Verge, even lighter-weight models have helped people with limited AI knowledge "vibe-hack," and hackers who once went only after the most valuable targets can now take a shotgun approach [16]. "What would have otherwise required maybe a team of sophisticated actors," Jacob Klein, head of Anthropic's threat intelligence team, told The Verge, "now, a single individual can conduct, with the assistance of agentic systems" [9]. Marius Hobbhahn, CEO of Apollo Research, was more specific about where he expects the damage to land. "I expect the harm to be felt by a random Idaho hospital," he said [14].
In this record, most of the harm to small institutions is still a forecast. Malone cannot say whether AI was involved in her case [6]. Hobbhahn's hospital is an expectation, and Michael Kleinman, a policy head quoted by The Verge, describes small and mid-size institutions as particularly at risk [15]. The documented AI-assisted campaign is the extortion run Anthropic described in August 2025 [8], and The Verge's account does not give the size of those victims. The access gap is documented. The Verge also judges that even wider access would likely be too expensive for many smaller organisations [13].
For whoever runs IT at a clinic or a small nonprofit, I would sort the decision on two axes. One is whether your systems hold other people's sensitive data, as Vivian's Door held financial data on the businesses it served [2]. The other is who learns of a breach first: your own tools, or the people in your address book.
Vivian's Door sat in the box with sensitive data and outside detection. In that box I think the first dollar goes to hearing about a breach before your contacts do, and the second to a recovery contract priced before anything goes wrong. An organisation with sensitive data and working detection has patch speed as its main remaining risk, and patch speed belongs to the vendors on the labs' list [11]. Groups holding no one else's data stand to lose mostly their name, and for them waiting on vendor patches is a defensible plan. Detection spending has a cost of its own. A quiet year shows nothing for the money, and it does nothing about a flaw a listed vendor already knows about and has not yet fixed.
What to watch
- Whether Anthropic or OpenAI open Mythos or Astra beyond the current list, or price a tier small organisations could afford.
- Whether any breach at a small hospital, bank or nonprofit is publicly attributed to AI-assisted attackers, turning Hobbhahn's forecast into a documented case.
- How fast Microsoft and other listed vendors clear the Mythos-flagged backlog, since that pace is the protection small organisations actually receive.