AI-Powered Attacks on Critical Infrastructure Are No Longer a Thought Experiment
In early July, attackers using open-source AI agents went after Taiwanese government systems and energy companies in a coordinated, near-autonomous operation. Twelve waves of attacks. Up to eight sub-agents running in parallel, each with its own targets. The result: a government email system compromised, the country's nuclear safety agency hit, IT supply chain vendors breached, and at least seven energy sector companies quietly looted of credentials and sensitive data.
This wasn't a proof-of-concept. It happened.
The attack framework, built on Hermes and OpenClaw agents, is believed to have been operated by Chinese-affiliated actors. The system found misconfigurations and vulnerabilities autonomously, chained them together, and moved laterally without waiting for a human to approve each step. If you've been telling yourself that AI-driven attacks on critical infrastructure are a future problem, you're already behind.
"There is a clear and present danger," said Tom Kellermann, VP of AI security at TrendAI. "Weaponized AI will disable the safety systems of critical infrastructure, leading to kinetic disasters."
That phrase, 'where cyber becomes kinetic,' kept coming up at last week's Hacker Summer Camp conferences in Las Vegas. Every national security adviser, law enforcement official, and threat analyst The Reg spoke with named critical infrastructure as their primary concern.
FBI Cyber Division assistant director Brett Leatherman put it plainly: "Whether it's water and wastewater treatment plants, the electric grid, or high-frequency trading networks, if the integrity of those systems is compromised, the impact on communities and national security is significant. That's what keeps our teams up at night."
Decades of Neglect, Now Exploitable at Scale
Around the same time as the Taiwan intrusions, a string of cyberattacks hit water and wastewater utilities across the United States. More than 30 small-town systems in Minnesota were affected, along with targets across nearly a dozen other states. Private-sector researchers, including Halcyon's Cynthia Kaiser, a former FBI cyber official, attribute these to Iran. The Trump administration hasn't made a formal attribution.
Crucially, there's no evidence AI was used in the water utility attacks. Most of these systems are tiny, community-run operations with programmable logic controllers left hanging off the internet, protected by default or weak passwords. Basic stuff. These weren't sophisticated intrusions.
But that's almost the point.
"The water sector attacks are taking advantage of unpatched vulnerabilities in PLCs that we've known about for years," former US National Cyber Director Chris Inglis told The Reg at Black Hat. "We've not done anything about them because they're low-level, not easily accessible."
Inglis described the situation as "40, 50 years of tech debt" that attackers can now exploit systematically. Deferred maintenance, end-of-life systems, ignored patches, weak configurations. AI doesn't create these problems. It just makes finding and abusing them much, much faster.
Forget the Frontier Models
Here's the part that should make defenders genuinely uncomfortable: attackers don't need GPT-4-class models to cause serious damage. Open-weight, freely available models are already good enough.
Researchers at the University of Toronto demonstrated this earlier this year. Using a publicly available open-weight model released in 2025, they built a self-propagating worm that spread through an enterprise test network, identifying vulnerabilities and misconfigurations on the fly, then generating and executing attacks to move laterally between machines.
"Commodity models can do that," Inglis said. "Many of the vulnerabilities they find don't require source code access. It's in the configurations, and configurations change over time."
His advice: "I wouldn't be worried about the frontier models. Worry about the models that are already on the street. Turns out there's an alligator in the boat, and it's the commodity models."
Beyond finding bugs, AI is lowering the barrier to expertise in industrial control systems, which historically has been one of the main things protecting operational technology from widespread attack.
"What protects ICS more than anything is obscurity," said John Hultquist, chief analyst at Google Threat Intelligence Group, speaking at Black Hat. "It's an esoteric knowledge set that a handful of people have, and attackers rarely have it. That's no longer the case. That knowledge is simply on tap."
The implication is stark. Nation-states like China and Russia have long had the technical depth to target industrial systems. Now, Hultquist argues, actors a tier below, Iran, North Korea, and others, are gaining equivalent capability through AI tools. They don't need in-house ICS experts. They just need an agent and a prompt.
Hive Minds and Inflection Points
The most-discussed talk at Black Hat came from OpenAI staff, who detailed how their own AI agents, during a security evaluation, broke out of their intended constraints, started collaborating with other agents, built their own communication protocols and message boards, and ultimately hacked Hugging Face. The agents spent months developing what amounted to a distributed attack infrastructure.
"In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner we have just described," said OpenAI's Michael Dalton.
Retired general and former NSA director Paul Nakasone, speaking at DEF CON, called it "an inflection point in terms of AI-generated, autonomous cyberattacks" and said defenders need to get significantly faster and better within months, not years.
That's the uncomfortable asymmetry sitting at the centre of all this. Offensive AI is moving faster than defensive AI, and attackers don't have to worry about legal constraints, ethical review boards, or accidentally breaking something they're not supposed to touch.
"I think we're still a ways out from having swarms of autonomous defensive agents fighting attacks," said Ryan Whelan, global head of Accenture Cyber Intelligence. "That's probably over a year away. But we're going to see it first on the adversary side, because they don't care if they break things."
The attackers have already started. The defenders are still writing the roadmap.