Safety

AI-generated text

AI Lowers the Technical Barrier for Hackers Targeting Critical Infrastructure

Recent cyberattacks against U.S.

AI Lowers the Technical Barrier for Hackers Targeting Critical Infrastructure

A recent wave of cyberattacks against U.S. water systems and a British power plant has highlighted how artificial intelligence (AI) is making existing digital weaknesses in critical infrastructure easier for attackers to exploit.

What happened

The Telegraph reported that Iran-backed hackers breached a U.K. power plant, causing a four-day shutdown. That incident coincided with a series of cyberattacks affecting U.S. water systems. U.S. officials warned last week that attackers were actively using an AI-generated exploitation script to target a device commonly found in critical infrastructure — an element that has been central to the ongoing attacks on U.S. water systems.

Markus Mueller, field CISO at critical infrastructure security firm Nozomi Networks, told Axios he has medium confidence the U.K. and U.S. incidents are linked to the same threat actor.

Why it matters

Policymakers have long warned that weak cybersecurity across critical infrastructure could produce real-world harms. Five years ago, Sen. Angus King (I-Maine) told Congress that vulnerabilities at U.S. water utilities posed “an extremely dangerous situation,” noting that the United States is highly connected but also highly vulnerable.

How AI changes the equation

Experts say AI does not fundamentally change how attackers break into industrial systems, but it reduces the time, cost and expertise required to understand specialized equipment and craft working exploits. Diana Kelley, chief information security officer at Noma Security, told Axios that AI lowers the "time, cost, and expertise needed to take advantage of weaknesses that already exist."

Historically, threat actors often needed physical access to devices or to study technical manuals before they could successfully target specialized components such as programmable logic controllers. AI tools can now automate parts of that process and accelerate the creation of exploit code.

Government and regulatory response

Governments have not ignored the issue, but attempts to impose stronger security requirements have proceeded slowly and encountered legal, political and funding obstacles. During the Biden administration, the Environmental Protection Agency (EPA) tried to require basic cybersecurity measures for water utilities, but the policy was later rescinded after legal challenges from states and industry groups.

Mayuresh Dani, a security research manager at Qualys, warned that recent federal cuts to cybersecurity resources and uncertainty around grant funding for state and local governments leave communities more vulnerable to future cyberattacks. John Gallagher, vice president at automated cybersecurity firm Viakoo, noted that guidance and advisories alone will struggle to keep pace because defensive efforts are often constrained by bureaucratic budget cycles and multiyear legislative processes.

Impact so far and remaining unknowns

So far, the recent incidents have caused only limited disruptions. In some towns, attackers altered local water pressure and officials issued precautionary boil-water advisories. The Telegraph reported that the cyberattack on the local U.K. power plant "had no impact on the U.K.'s wider power supply or energy generation."

Key details about the U.K. incident remain unclear, including the type of power plant targeted and which devices were accessed, Mueller said.

Why critical infrastructure remains an attractive target

Margaret Cunningham, vice president of security and AI strategy at Darktrace, said critical infrastructure is appealing to nation-state actors because even relatively small disruptions can produce highly visible consequences. "AI gives attackers more speed and reach, but it doesn't erase the problems critical infrastructure organizations have been dealing with for years, including exposed operational technology, difficulty patching and systems that cannot simply be switched off," she said.

What to watch next

Investigators' findings about the U.K. power plant and any attribution updates will be important, as will policy and funding decisions that affect the ability of local utilities to implement stronger cybersecurity measures. Security leaders and policymakers will need to factor in how AI reduces barriers for attackers when designing defenses and regulatory approaches.


Sources cited in this report include The Telegraph, U.S. government statements, and comments from security experts Markus Mueller (Nozomi Networks), Diana Kelley (Noma Security), Mayuresh Dani (Qualys), John Gallagher (Viakoo) and Margaret Cunningham (Darktrace).