Sunday, 16 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Autonomous AI attacks pose 'clear and present danger' to critical infrastructure

The Register ·
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure

In early July, attackers used open source AI agents to autonomously hack government systems and energy companies, signaling to defenders that AI-powered attacks against critical infrastructure are no longer theoretical.

"There is a clear and present danger," Tom Kellermann, TrendAI VP of AI security and threat research, told The Register.

"As the geopolitical tension boils, systemic destructive cyberattacks launched by autonomous AI will occur," he said.

"Weaponized AI will disable the safety systems of critical infrastructure, thus leading to kinetic disasters.

Just like we see autonomous strike vehicles operating on the battlefield in Ukraine, we should expect autonomous weaponized AI." In fact, the prospect of attackers using AI against critical infrastructure was the top concern of every national security adviser, law enforcement official, and private-sector threat analyst The Reg spoke with at last week's Hacker Summer Camp conferences.

"It's the targeting of critical infrastructure for us," Brett Leatherman, assistant director of the FBI's Cyber Division, told us during an interview at Black Hat.

"We're very focused on the downstream impact targeting of critical infrastructure," Leatherman said.

"That is where cyber becomes kinetic, and whether it is our water and wastewater treatment plants, whether it's the electric grid, whether it's the high-frequency trading networks and the financial networks, all of those, if the integrity of those are compromised, will have significant impact to communities and national security.

So that's what keeps our teams up at night.

How are we moving to secure critical infrastructure?" Where cyber becomes kinetic During the first four days of July, suspected Chinese operators aimed an attack framework built on Hermes and OpenClaw AI agents at targets in Taiwan.

Across 12 "attack waves," the "near-autonomous" system deployed up to eight sub-agents, each assigned its own targets and techniques, and broke into a Taiwanese government website.

Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities while stealing sensitive data, credentials, and other secrets as they moved across the network.

The Taiwanese government intrusion also followed a series of cyberattacks against water and wastewater utilities in the United States.

While the Trump administration hasn't attributed these to a particular government or group, private sector threat hunters – including Halcyon Ransomware Research Center SVP Cynthia Kaiser, a former FBI cyber division deputy assistant director – blame Iran for these intrusions.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›