Tuesday, August 25, 2026 SourcesAbout🌓
🇺🇸 US ▾
BREAKING
Latest

AI is making critical infrastructure easier to attack

Axios ·
AI is making critical infrastructure easier to attack

Years of warnings about the digital vulnerabilities lurking inside basic utilities are colliding with a new reality: AI is making those weaknesses easier for hackers to exploit.

Why it matters: AI is lowering the barrier for state-backed hackers looking to disrupt or manipulate water systems, power plants and other critical infrastructure.

Driving the news: A recent wave of cyberattacks targeting critical infrastructure is raising new questions about the preparedness of U.S. water systems and a British power plant.

The Telegraph reported that Iran-backed hackers broke into a U.K. power plant, prompting a four-day shutdown around the time a series of cyberattacks on U.S. water systems began.

U.S. officials warned last week that hackers were actively using an AI-generated exploitation script to target a device commonly found in critical infrastructure that has played a key role in the ongoing attacks on U.S. water systems.

Markus Mueller, field CISO at critical infrastructure security firm Nozomi Networks, told Axios he has medium confidence that the U.S. and U.K. attacks are linked to the same threat actor.

The big picture: Policymakers have been warning for years that weak cybersecurity across critical infrastructure could eventually have real-world consequences.

Five years ago, Sen.

Angus King (I-Maine) warned Congress that cyber weaknesses across U.S. water utilities represented "an extremely dangerous situation." "We're the most wired country in the world.

That's good," he told lawmakers.

"But we're also the most vulnerable country in the world." Between the lines: AI isn't fundamentally changing how hackers break into these systems.

It's reducing the time and expertise needed to understand specialized equipment and exploit weaknesses that already exist, experts told Axios.

Suspected Iranian hackers have long studied U.S. critical infrastructure, including how specialized devices such as programmable logic controllers work.

Historically, threat actors might have needed to obtain the devices themselves or pore over technical manuals before they could successfully target them, Mueller said.

Read the full article on Axios ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.axios.com — the content belongs to Axios.

More from Axios

See all ›

More in Latest

See all ›