AI is supercharging hacking, and your local hospitals and banks aren’t ready

AI is supercharging hacking, and your local hospitals and banks aren’t ready

人工智能正在助长黑客攻击,而你身边的医院和银行却毫无准备

New models are helping Big Tech shore up its cyber defenses. What about everyone else? 新的模型正在帮助大型科技公司加强网络防御。但其他人该怎么办呢?

In March, Janice Malone began getting calls about suspicious activity from her nonprofit organization, Vivian’s Door. Vivian’s Door, headquartered in Alabama, typically provided training, resources, and community to underserved and minority-owned businesses. The work sometimes put it in close contact with these companies’ financial data, which was stored on its systems. But suddenly, concerned callers from all over the world warned they’d been getting emails “begging for money” — which she hadn’t sent. 今年三月,Janice Malone 开始接到关于其非营利组织“Vivian’s Door”存在可疑活动的电话。总部位于阿拉巴马州的 Vivian’s Door 通常为服务不足的少数族裔企业提供培训、资源和社区支持。这项工作有时会使其接触到这些公司的财务数据,并将其存储在自己的系统中。但突然间,来自世界各地的担忧者打来电话警告称,他们收到了“乞求钱财”的电子邮件——而这些邮件并非她所发。

The organization’s third-party IT team pulled its systems offline for three days while they investigated the issue and plugged up the vulnerability, leaving Malone with a bill of about $3,000. She feared that she’d exposed information about the companies she was trying to help. Even more ominously, she wasn’t completely sure if the attack was engineered by a human hacker or helped along by an AI system, or whether more were on the way. 该组织的第三方 IT 团队将系统离线了三天,以调查问题并修补漏洞,这让 Malone 收到了一张约 3000 美元的账单。她担心自己泄露了那些她试图帮助的公司的信息。更令人不安的是,她完全不确定这次攻击是由人类黑客策划的,还是在人工智能系统的帮助下完成的,也不知道未来是否还会有更多的攻击。

The past months have seen AI revolutionize the field of cybersecurity. OpenAI and Anthropic have disclosed that “rogue” systems escaped restrictions in their own labs and hacked everything from a small German wiki to the Australian government. Even before that, powerful models like Anthropic’s Mythos created an arms race to advance AI cybersecurity, and even lighter-weight models have allowed human bad actors to supercharge their hacking efforts. 过去几个月里,人工智能彻底改变了网络安全领域。OpenAI 和 Anthropic 披露称,一些“流氓”系统逃脱了其实验室的限制,入侵了从德国小型维基网站到澳大利亚政府系统的各种目标。在此之前,Anthropic 的 Mythos 等强大模型就已经引发了人工智能网络安全的军备竞赛,即便是更轻量级的模型,也让不法分子能够大幅增强其黑客攻击能力。

Malone isn’t sure whether AI was involved in the hack of Vivian’s Door. But amid stories of autonomous agent swarms and national security risks, she felt especially concerned. Big AI companies were bragging about finding vulnerabilities in “every major operating system and web browser” with new models, and their big-name clients were striking deals to defend themselves with those same tools. Where did that leave her? Malone 不确定人工智能是否参与了对 Vivian’s Door 的黑客攻击。但在关于自主智能体集群和国家安全风险的报道中,她感到格外担忧。大型人工智能公司吹嘘其新模型能发现“每一个主流操作系统和网络浏览器”中的漏洞,而它们的大牌客户也正通过协议利用这些工具进行防御。那么,她又该何去何从呢?

“Who knows about the next vulnerability? You only know about the one that you’ve been hit with,” Malone said, adding, “How do you protect yourself? I mean, really?” “谁知道下一个漏洞在哪里?你只知道那个已经让你中招的漏洞,”Malone 说道,并补充道,“你该如何保护自己?我是说,真正地保护自己?”

AI agents have become consistently, strikingly skilled at cybersecurity and coding, and they can be deployed at enormous scale. Even attackers with limited knowledge of AI can engage in “vibe-hacking” with these new, automated systems, and hackers who might once have focused on only the most valuable targets can take a shotgun approach. In August 2025, Anthropic said that a sophisticated cybercrime ring used Claude Code to extort data from healthcare organizations, emergency services, religious institutions, and even government entities, all in one month. 人工智能智能体在网络安全和编程方面已经变得非常且惊人地熟练,并且可以大规模部署。即使是对人工智能了解有限的攻击者,也能利用这些新的自动化系统进行“氛围黑客攻击”(vibe-hacking),而那些曾经只关注最有价值目标的黑客,现在也可以采取“散弹枪式”的攻击策略。2025 年 8 月,Anthropic 表示,一个复杂的网络犯罪团伙在一个月内利用 Claude Code 从医疗机构、紧急服务部门、宗教机构甚至政府实体中勒索数据。

“What would have otherwise required maybe a team of sophisticated actors,” Jacob Klein, head of Anthropic’s threat intelligence team, told The Verge in an interview at the time, “now, a single individual can conduct, with the assistance of agentic systems.” “原本可能需要一个复杂的黑客团队才能完成的事情,”Anthropic 威胁情报团队负责人 Jacob Klein 当时在接受 The Verge 采访时表示,“现在,在智能体系统的协助下,一个人就能完成。”

In theory, AI is also supposed to safeguard cyber defenses; Anthropic’s Mythos is reportedly flagging so many vulnerabilities that Microsoft is struggling to fix them fast enough. But out of concern over potential danger, top AI labs only allow a limited list of high-profile organizations to access their most powerful cybersecurity models, like Mythos and OpenAI’s Astra. That includes companies like Nvidia, Google, and Apple, as well as other “essential infrastructure providers” and “maintainers of critical open-source software.” Even if access was more widely available, it would likely be too expensive for many smaller organizations. 从理论上讲,人工智能也应该用于保障网络防御;据报道,Anthropic 的 Mythos 发现的漏洞多到让微软难以快速修复。但出于对潜在危险的担忧,顶级人工智能实验室仅允许少数知名组织访问其最强大的网络安全模型,如 Mythos 和 OpenAI 的 Astra。这包括英伟达、谷歌和苹果等公司,以及其他“关键基础设施提供商”和“关键开源软件维护者”。即使这些访问权限更广泛地开放,对于许多小型组织来说,费用也可能过于昂贵。

Now, these organizations — from healthcare clinics and municipalities to small retailers and nonprofits like Vivian’s Door — fear an increasingly lopsided power dynamic. As Marius Hobbhahn, CEO and cofounder of Apollo Research, put it in an interview with The Verge this summer, “A single person somewhere in a basement with one of the open-source models probably could hack a hospital and demand ransom. That’s where I expect a lot of the harm to be felt. It’s not in the Bay Area… I expect the harm to be felt by a random Idaho hospital.” 现在,这些组织——从医疗诊所和市政机构到小型零售商和像 Vivian’s Door 这样的非营利组织——担心权力对比会变得越来越失衡。正如 Apollo Research 的首席执行官兼联合创始人 Marius Hobbhahn 今年夏天在接受 The Verge 采访时所言:“某个地下室里的一个人,利用开源模型之一,可能就能黑进一家医院并勒索赎金。这就是我预计大部分伤害会发生的地方。不是在湾区……我预计伤害会发生在爱达荷州的一家普通医院身上。”

Small- and medium-size institutions are particularly at risk from AI agents supercharging a finite number of human hackers, says Michael Kleinman, head of US policy for the Future of Life Institute, a nonprofit focused on reducing large-scale risks of tech. And despite being small, these institutions provide vital services to their users. “Bank of America has a lot of resources to throw at this — what about community level banks? What about savings and loans? What about credit unions? What about local hospital networks? What about local power grids?” Kleinman said. “The limiting factor used to be that there’s a finite number of malicious hackers in the world, and that’s now no longer the case.” 专注于降低大规模技术风险的非营利组织“生命未来研究所”(Future of Life Institute)美国政策负责人 Michael Kleinman 表示,中小型机构尤其容易受到人工智能智能体助长的黑客攻击。尽管规模较小,但这些机构为用户提供了至关重要的服务。“美国银行有大量资源来应对这个问题——但社区银行呢?储蓄贷款机构呢?信用合作社呢?当地医院网络呢?当地电网呢?”Kleinman 说,“过去,限制因素是世界上恶意黑客的数量有限,但现在情况已不再如此。”

Malone of Vivian’s Door said that like most small businesses or nonprofits, she doesn’t have the resources for round-the-clock cybersecurity forces or IT staff hunting for unknown threats. “I just don’t know how you can really be, as a small business, totally protected on the budgets you have to do IT with,” she said. Vivian’s Door 的 Malone 表示,像大多数小企业或非营利组织一样,她没有资源来维持全天候的网络安全力量或专门搜寻未知威胁的 IT 人员。“我只是不知道作为一个小企业,在有限的 IT 预算下,如何才能真正做到完全受到保护,”她说。