In March 2026, a cyberattack on a water treatment facility in the Netherlands caused a 72-hour disruption to water services for approximately 400,000 residents. The attack was notable not for its scale — water utility attacks have occurred before — but for its method. Post-incident analysis by Dutch cybersecurity authorities and ENISA (the EU's cybersecurity agency) concluded that the attack had used AI-generated malware that had automatically adapted to the facility's specific industrial control system, evading detection by signature-based security tools that had never seen the specific code before.

It was not an isolated incident. In the first half of 2026, cybersecurity firms including CrowdStrike, Mandiant, and Palo Alto Networks have all published reports documenting a significant increase in AI-assisted cyberattacks against critical infrastructure — power grids, water systems, financial networks, hospitals, and telecommunications. The threat is real, it is growing, and the gap between attacker capability and defender readiness is widening.

How AI Is Changing the Cyberattack Landscape

To understand the AI-powered threat, it helps to understand what the attack cycle looks like and where AI is being applied.

A sophisticated cyberattack typically involves several phases: reconnaissance (gathering information about the target), initial access (finding and exploiting a vulnerability to get into the network), lateral movement (spreading through the network to reach high-value targets), persistence (establishing a foothold that survives reboots and security responses), and the final objective (data theft, ransomware deployment, or sabotage).

AI is being applied across all of these phases, but its impact is most significant in three areas:

Automated vulnerability discovery: Finding exploitable vulnerabilities in complex software systems has historically required skilled human researchers working for days or weeks. AI systems can now scan codebases, network configurations, and running systems to identify potential vulnerabilities at machine speed. A 2025 DARPA competition demonstrated that AI systems could discover and exploit novel vulnerabilities in complex software with no human assistance — a capability that was theoretical just two years earlier.

Novel malware generation: Traditional malware detection relies heavily on signatures — known patterns in malicious code that security tools are trained to recognise. AI can generate functionally equivalent malware with different code structures, making signature-based detection ineffective. More concerning, AI can generate malware tailored to specific target environments — adapting to the specific software versions, network configurations, and security tools present in a target organisation.

Spear phishing at scale: Phishing — tricking users into revealing credentials or clicking malicious links — remains the most common initial access vector. AI has dramatically improved the quality and scale of phishing attacks. Large language models can generate highly personalised phishing emails that reference real details about the target — their job role, recent projects, colleagues' names — making them far more convincing than the generic phishing emails of the past. What previously required a skilled social engineer to craft for each target can now be generated automatically for thousands of targets simultaneously.

Who Is Behind the Attacks

The AI-powered threat comes from multiple directions, each with different motivations and capabilities.

Nation-state actors: The most sophisticated AI-powered attacks are attributed to nation-state groups, primarily from Russia, China, North Korea, and Iran. These groups have the resources to develop or acquire advanced AI capabilities and the strategic motivation to target critical infrastructure. Russia's Sandworm group — responsible for the 2015 and 2016 Ukrainian power grid attacks — has been linked to AI-assisted reconnaissance operations against European energy infrastructure. China's Volt Typhoon group has been documented conducting long-term, stealthy intrusions into US critical infrastructure, with AI-assisted lateral movement techniques that evade traditional detection.

Ransomware criminal groups: Financially motivated ransomware groups have been quick to adopt AI tools to improve their operational efficiency. The LockBit and BlackCat ransomware groups — before their partial disruption by law enforcement — were documented using AI to automate the identification of high-value targets within compromised networks and to generate ransom demands personalised to the victim's financial profile. The adoption of AI by criminal groups has lowered the skill barrier for conducting sophisticated attacks, expanding the pool of potential attackers.

Hacktivists and lone actors: AI tools have also democratised attack capability for less sophisticated actors. Open-source AI models and commercially available AI services can be used to generate basic malware, conduct automated vulnerability scanning, and craft phishing campaigns without deep technical expertise. This has expanded the threat landscape beyond the nation-state and organised criminal groups that have historically dominated sophisticated attacks.

Critical Infrastructure: The Highest-Stakes Targets

Critical infrastructure — the systems that modern society depends on for basic functioning — represents the highest-stakes target for cyberattacks. The consequences of a successful attack on a power grid, water system, or financial network extend far beyond the immediate victim organisation.

The power grid is particularly concerning. Modern electricity grids are increasingly interconnected and digitally controlled, creating attack surfaces that did not exist in the era of purely mechanical systems. A successful attack on grid control systems could cause cascading failures affecting millions of people. The 2015 and 2016 attacks on Ukraine's power grid — which caused widespread blackouts — demonstrated that this threat is not theoretical.

Water treatment facilities are another high-priority target. The 2021 attack on the Oldsmar, Florida water treatment plant — where an attacker remotely increased sodium hydroxide levels to potentially dangerous concentrations — highlighted the vulnerability of water infrastructure. The Netherlands incident in 2026 demonstrated that AI-powered attacks can overcome the security improvements that many utilities implemented after Oldsmar.

Hospitals represent a particularly morally troubling target. Ransomware attacks on hospitals have increased significantly in recent years, with attackers calculating that the urgency of patient care creates pressure to pay ransoms quickly. AI-powered attacks that can identify and encrypt critical patient data systems faster than human defenders can respond represent a genuine threat to patient safety.

The Defence Response: AI vs AI

The cybersecurity industry's response to AI-powered attacks is, inevitably, to deploy AI in defence. This is creating a dynamic that security researchers describe as an "AI arms race" — with offensive and defensive AI capabilities escalating in parallel.

AI-powered security tools are being deployed across several defensive functions. Behavioural anomaly detection — identifying unusual patterns in network traffic, user behaviour, and system activity that might indicate an intrusion — is an area where AI significantly outperforms rule-based systems. AI can establish a baseline of normal behaviour for a network and flag deviations in real time, catching attackers who have successfully evaded signature-based detection.

Automated threat hunting — proactively searching for indicators of compromise rather than waiting for alerts — is another high-value AI application. Security teams at large organisations are using AI to analyse vast quantities of log data and identify subtle patterns that human analysts would miss or take days to find.

Vulnerability management — identifying and prioritising the patching of security vulnerabilities — is being transformed by AI. Traditional vulnerability management involves scanning for known vulnerabilities and prioritising patches based on severity scores. AI can predict which vulnerabilities are most likely to be exploited in the near term based on threat intelligence, attacker behaviour patterns, and the specific characteristics of the target environment.

Government and Regulatory Response

Governments worldwide are responding to the AI-powered threat with a combination of regulatory requirements, investment in defensive capabilities, and international coordination.

In the United States, CISA (the Cybersecurity and Infrastructure Security Agency) has issued binding operational directives requiring federal agencies to implement specific AI-powered security controls and has published guidance for critical infrastructure operators on defending against AI-assisted attacks. The Biden administration's National Cybersecurity Strategy, updated in 2025, explicitly addresses AI-powered threats and requires critical infrastructure operators to meet minimum cybersecurity standards.

The EU's NIS2 Directive, which came into force in 2024, significantly expanded the scope of mandatory cybersecurity requirements for critical infrastructure operators and introduced substantial penalties for non-compliance. The directive explicitly requires operators to assess and address AI-related threats as part of their risk management frameworks.

International coordination remains challenging. Attributing cyberattacks to specific nation-state actors is technically difficult and politically sensitive. The lack of binding international norms around cyberattacks on critical infrastructure — analogous to the laws of armed conflict that govern kinetic warfare — means that nation-state actors face limited consequences for attacks that fall below the threshold of armed conflict.

What Organisations Can Do

For organisations responsible for critical infrastructure, the AI-powered threat requires a fundamental reassessment of security posture. Several measures are particularly important:

Network segmentation — isolating operational technology (OT) systems from IT networks and the internet — remains the most effective defence against attacks that target industrial control systems. Many critical infrastructure operators have historically connected OT and IT networks for operational convenience; the security cost of this convenience is increasingly untenable.

Zero-trust architecture — requiring continuous verification of every user and device attempting to access systems, rather than trusting anything inside the network perimeter — is becoming the baseline security model for critical infrastructure. AI-powered identity verification and continuous behavioural monitoring are essential components of effective zero-trust implementation.

Incident response planning and regular exercises are critical. The question for critical infrastructure operators is not whether they will be attacked but when. Organisations that have practised their response to a major cyber incident — including communication protocols, manual fallback procedures, and coordination with government agencies — recover significantly faster than those that have not.

Źródła i dalsze czytanie