What’s Actually Happening
U.S. officials have warned that hackers are actively using an AI-generated exploitation script to target a device commonly found across critical infrastructure—one that has played a central role in the ongoing wave of attacks on U.S. water systems. Separately, Iran-backed hackers reportedly broke into a U.K. power plant, triggering a four-day shutdown around the same period.
Markus Mueller, field CISO at critical infrastructure security firm Nozomi Networks, has stated medium confidence that the U.S. and U.K. incidents are linked to the same threat actor. Key details about the U.K. attack remain unclear, including the type of facility targeted and which specific devices were accessed.
The immediate impact has been limited. Some towns experienced altered water pressure levels and issued precautionary boil-water advisories. The U.K. power plant attack reportedly had no effect on broader national energy supply. But limited disruption is not the same as low risk.
What AI Is Actually Changing
AI is not rewriting the playbook for infrastructure attacks. It is accelerating execution of an existing one.
Suspected Iranian hackers have long studied U.S. critical infrastructure, including how specialized devices like programmable logic controllers (PLCs) operate. Historically, that required obtaining physical hardware, studying technical manuals, or building deep domain expertise over time. AI is shortcutting that process.
Diana Kelley, CISO at Noma Security, described it precisely: AI lowers the “time, cost, and expertise needed to take advantage of weaknesses that already exist.” The vulnerabilities in operational technology (OT) environments are not new. The speed at which adversaries can now understand and exploit them is, including through an AI-generated exploitation script.
The Structural Problem
Critical infrastructure—particularly water utilities—operates on systems that were built for reliability and longevity, not security. Operational technology environments often run legacy equipment that cannot be easily patched, updated, or taken offline without service disruption. These are not edge cases. They are the norm.
Margaret Cunningham, VP of security and AI strategy at Darktrace, put it plainly: “AI gives attackers more speed and reach, but it doesn’t erase the problems critical infrastructure organizations have been dealing with for years, including exposed operational technology, difficulty patching and systems that cannot simply be switched off.”
The exposure is structural, and it predates AI by decades.
Why Policy Has Not Kept Pace
Governments have not ignored the problem entirely, but progress has been slow and repeatedly interrupted.
- The EPA attempted under the Biden administration to require water utilities to implement basic cybersecurity measures. The policy was later rescinded following legal challenges from states and industry groups.
- Recent federal cuts to cybersecurity resources, combined with uncertainty around grant funding for state and local governments, have left communities more exposed.
- Cyber hygiene guidance and government advisories are not sufficient on their own. As John Gallagher, VP at automated cybersecurity firm Viakoo, noted: “Adversaries will always have an upper hand because of speed when cyber defense relies on bureaucratic budget cycles and multiyear legislative processes.”
Senator Angus King warned Congress five years ago that cybersecurity weaknesses across U.S. water utilities represented “an extremely dangerous situation.” That assessment has not aged well for the defenders.
The Asymmetry That Matters
Nation-state hackers target critical infrastructure not because they expect catastrophic damage on the first attempt, but because even minor disruptions carry outsized visibility and psychological impact. A boil-water advisory in a mid-sized city, a four-day power plant shutdown—these events erode public confidence and signal vulnerability to adversaries watching closely.
AI amplifies this asymmetry. Attackers gain speed and reach. Defenders remain constrained by procurement timelines, regulatory complexity, and aging infrastructure that cannot simply be switched off for an upgrade cycle.
What to Watch
The U.K. power plant incident still has significant unknowns—facility type, targeted devices, and full scope of access remain unconfirmed. Whether the U.S. and U.K. attacks share a common threat actor will matter for how defenders prioritize response and attribution.
More broadly, the question is no longer whether AI will be used to accelerate attacks on critical infrastructure. It already is. The more pressing question is whether the institutions responsible for defending these systems can move faster than the budget cycles and legislative processes that currently govern them.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!