MIT Cybersecurity Clinic Treats Human Flaw in Ransomware Attacks
In May 2019, Baltimore’s municipal government collapsed into digital paralysis. Cybercriminals had encrypted critical files across city systems, demanding payment to restore access. The city refused. For weeks, real estate transactions froze, bill payments stopped, and recovery costs climbed into the millions. The attack did not exploit a sophisticated technical vulnerability. It exploited people — the same human element that remains cybersecurity’s weakest link today, according to the MIT Cybersecurity Clinic’s research.
The Discovery That Changed Everything
The clinic’s founders, Lecturer Jungwoo Chun and Professor Lawrence Susskind, discovered something counterintuitive while studying ransomware attacks on public agencies. They found that the most devastating breaches did not result from advanced hacker tools or zero-day exploits. Instead, attackers consistently succeeded by manipulating human psychology — tricking employees into sending money, downloading malicious code, or revealing sensitive information. This discovery, documented in the clinic’s case studies including the Baltimore incident, shifted their entire approach away from purely technical solutions.
The MIT Cybersecurity Clinic launched in 2019 within the Department of Urban Studies and Planning, not the computer science department. This placement was deliberate. Chun, an applied social scientist, and Susskind, a conflict resolution scholar, recognized that cybersecurity required understanding how people make decisions under pressure. They called their approach “defensive social engineering” — a term that acknowledges the attacker’s primary tool is human manipulation, not code.
By 2026, the clinic has trained hundreds of students across multiple semesters, each cohort learning that firewalls and encryption mean nothing if an employee clicks a malicious link. The course begins with four weeks of intensive preparation, including simulations of difficult client interactions. Students practice what happens when clients dismiss their expertise or argue for more favorable assessments than facts warrant. These scenarios mirror real-world challenges, as MIT student Diego Contreras noted: “I’ve never ever had a class that prepared us for such realistic scenarios before.”
Who Decides, Who Bears the Consequence
The clinic’s clients are small municipalities and healthcare organizations — entities that cannot afford dedicated cybersecurity staff. According to FBI data from 2025, cybercriminals launch an average of 2,765 attacks targeting Americans every day. When these attacks hit public agencies, the consequences cascade beyond financial losses. Water supplies have been compromised. 911 services have been blocked. Citizens’ personal data has been exposed. The decision-makers in these organizations are often town managers, hospital administrators, or IT directors with limited budgets and competing priorities.
The clinic’s students must navigate these power dynamics. Susskind explains that “the IT director can’t just do what she or he wants. They depend on the local government for their budget. They need approval to hire new staff.” This reality forces students to understand leadership dynamics within client communities. A computer science student might propose an elegant technical solution, but it means nothing if the town council cannot afford it or the hospital board does not understand its necessity.
Between 2018 and 2024, Comparitech documented 525 ransomware attacks on U.S. government entities — approximately one every five days. These attacks caused an estimated $1.09 billion in downtime costs. The victims are not corporate giants with dedicated security teams. They are underfunded public bodies that, as Susskind puts it, “need to follow a self-help pathway.” The clinic provides that pathway through low-cost, actionable recommendations that these organizations can implement with coaching.
The clinic’s students come from diverse backgrounds. Some are computer science majors who initially question why so much emphasis falls on organizational capacity rather than technical fixes. Others are planning or social science students who study smart city innovations without understanding the associated risks. The course forces both groups to confront their blind spots. Engineering students learn about leadership dynamics and budget constraints. Social science students learn about AI vulnerabilities and system design.

The Last Open Variable
Artificial intelligence has transformed the cybersecurity landscape in ways that even experts struggle to track. Chun acknowledges that ‘now AI can not only identify the vulnerability, but do the attack itself, which is really scary.’ But the fundamental insight remains unchanged: the biggest attack vector is still through humans.
The clinic’s students complete field assignments after passing a certification exam. Each team produces a confidential assessment of their client’s vulnerabilities, with recommendations tailored to the organization’s specific constraints. The most critical recommendations address human behavior: training employees to recognize phishing attempts, creating cultures where reporting suspicious activity is encouraged, and ensuring that cybersecurity considerations are embedded in every decision.
For students like Zev Moore, who studied mathematical economics and finance, the most delicate aspect was balancing assessment findings with client relationships. “Our approach was to provide important feedback while simultaneously validating the positive security measures our client already had in place,” Moore said. This balance ensures that reports feel like collaborative roadmaps rather than accusatory audits. The clinic has provided more than 40 such assessments, free of charge, primarily for New England municipalities and healthcare organizations.
The clinic addresses the rapid pace of change by inviting at least half a dozen guest speakers each semester from industry, other universities, and relevant public agencies. These speakers include specialists in AI-driven threats, cyber law, and operational technology security. The goal is not to produce cybersecurity experts but to create professionals who understand how to integrate security thinking into any organization.
The last open variable is whether these organizations will implement the clinic’s recommendations. The clinic provides the roadmap, but the journey belongs to the clients. Some cities and hospitals have adopted the clinic’s suggestions and strengthened their defenses. Others, constrained by budgets or competing priorities, have not. The clinic’s founders acknowledge that their work is never finished. New attacks emerge. New technologies create new vulnerabilities. New employees need training. The clinic continues to operate, semester after semester, because the human element that makes organizations vulnerable also makes them capable of change.
Source: MIT News
Sources
2. MIT Department of Urban Studies and Planning
3. Comparitech
