AI Makes Critical Infrastructure Easier for Hackers to Exploit
Why It Matters
AI lowers the barrier for state-sponsored hackers aiming to disrupt or manipulate vital systems like water plants, power grids, or other critical networks. This does not mean hackers use entirely new methods, but AI helps them reach their goals faster by reducing the time, cost, and expertise required to understand specialized equipment and find weak points.
Latest news:
Recent Example Heightens Concerns
A recent wave of cyberattacks targeting critical infrastructure has raised questions about the preparedness of U. S. water systems and a British power plant. According to reports, Iran-backed hackers infiltrated a UK power station, causing a four-day shutdown, while launching a series of attacks on U. S. water systems. U. S. officials warned that hackers are actively using an AI-generated exploit script to target a common device in critical infrastructure—a component that played a key role in ongoing attacks on American water networks.
Expert Insights
Markus Mueller, field CISO at Nozomi Networks, told Axios he has moderate confidence that the U. S. and UK attacks are linked to the same threat actor. He explained that while dangerous actors once needed to buy physical devices or study technical manuals to understand how systems worked, AI now lets them skip that step, accelerating the identification of vulnerabilities.
Diana Kelley, CISO at Noma Security, confirmed this observation, saying AI does not fundamentally change how hackers enter systems but drastically reduces the time, cost, and expertise needed to exploit existing vulnerabilities. This means even actors with limited resources or little technical experience can now launch effective attacks against systems that, while not fundamentally unprotected, have known security gaps.
Long-Standing Problem
The issue is not new. For years, policymakers have warned that cybersecurity gaps in critical infrastructure could lead to real-world consequences. Five years ago, Senator Angus King (independent, Maine) warned Congress that vulnerabilities in U. S. water utilities represent „an extremely dangerous situation.” He noted, „We are the most connected country in the world. That’s good. But we are also the most vulnerable country in the world.” This tension between connectivity and vulnerability remains central to national security debates.
Slow Progress on Solutions
Although authorities have not ignored the problem, progress in applying stricter standards has been slow and blocked by legal, political, and financial obstacles. For example, the Environmental Protection Agency attempted under the Biden administration to impose basic cybersecurity measures for water utilities but withdrew the policy due to legal challenges from states and industry groups. Additionally, recent cuts to federal cybersecurity budgets and uncertainty about grants for state and local governments have left communities more exposed to future attacks, according to Mayuresh Dani, research manager at Qualys.
Conclusion
AI does not create new vulnerabilities but makes existing ones more accessible. Without accelerated efforts to improve defenses—through investment, clear regulation, and public-private collaboration—the risk that cyberattacks cause serious disruptions to daily life will continue to grow.
More stories: