{"id":52586,"date":"2026-03-09T11:24:28","date_gmt":"2026-03-09T11:24:28","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=52586"},"modified":"2026-04-13T17:09:56","modified_gmt":"2026-04-13T16:09:56","slug":"ai-cyber-conflict-and-the-new-frontline-the-growing-risk-to-us-critical-infrastructure","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2026\/03\/09\/ai-cyber-conflict-and-the-new-frontline-the-growing-risk-to-us-critical-infrastructure\/","title":{"rendered":"AI, cyber conflict and the new frontline: The growing risk to US critical infrastructure"},"content":{"rendered":"\n<p><em>A new CloudSEK report warns that the convergence of Artificial Intelligence tools, expanding Internet-exposed industrial systems and ideologically motivated cyber actors is reshaping the threat landscape facing US critical infrastructure.<\/em><\/p>\n\n\n\n<p>In modern geopolitical conflict, cyber operations have increasingly become a parallel battlefield. A recent CloudSEK report, <em>AI, the Iran-US Conflict and the Threat to US Critical Infrastructure<\/em>,\u2019 argues that the latest escalation between the United States and Iran may mark a turning point in how cyberthreats against industrial infrastructure emerge and scale.<\/p>\n\n\n\n<p>According to the report, within hours of the 28 February 2026 US &#8211; Israeli strikes against Iran, more than 60 Iranian-aligned cyber groups mobilised online, signalling one of the largest single-event cyber activations tied to a geopolitical crisis.<\/p>\n\n\n\n<p>What distinguishes this moment from previous cyber escalations, the report argues, is not merely the number of actors involved. It is the convergence of accessible Artificial Intelligence tools, a rapidly expanding attack surface of Internet-exposed industrial systems and a decentralised ecosystem of cyber actors motivated by ideology or retaliation.<\/p>\n\n\n\n<p>Together, these trends are reshaping the threat landscape for US critical infrastructure.<\/p>\n\n\n\n<p><strong>A long-building cyber conflict<\/strong><\/p>\n\n\n\n<p>As the CloudSEK report notes, the cyber dimension of the Iran \u2013 Israel &#8211; US confrontation has been evolving for more than a decade. Early incidents already demonstrated the strategic value of cyber operations against infrastructure targets.<\/p>\n\n\n\n<p>In 2012, the Shamoon malware attack destroyed roughly 30,000 systems at Saudi Aramco, marking one of the most destructive cyber incidents in the energy sector.<\/p>\n\n\n\n<p>Several years later, the 2017 TRITON\/TRISIS malware targeted safety systems at a Saudi petrochemical plant, representing the first known malware designed specifically to manipulate industrial safety instrumented systems (SIS).<\/p>\n\n\n\n<p>These attacks required significant technical expertise and resources typically associated with nation-state actors.<\/p>\n\n\n\n<p>But according to the CloudSEK report, the barrier to entry has steadily eroded since then. By 2023, Iranian-aligned groups had already begun targeting industrial equipment in Western countries.<\/p>\n\n\n\n<p>One of the most visible examples was the activity of the group CyberAv3ngers, which focused on Unitronics programmable logic controllers (PLCs) used in water, energy and manufacturing infrastructure.<\/p>\n\n\n\n<p>In November 2023, CyberAv3ngers compromised devices at a municipal water facility in Aliquippa, Pennsylvania, exploiting a default password on Internet-connected equipment.<\/p>\n\n\n\n<p>The US Cybersecurity and Infrastructure Security Agency (CISA) later confirmed that more than 75 US industrial devices were affected during the campaign.<\/p>\n\n\n\n<p>The incident demonstrated how relatively simple weaknesses &#8211; such as exposed management interfaces and default credentials &#8211; can translate into operational disruption when targeted by motivated actors.<\/p>\n\n\n\n<p><strong>The expanding threat actor ecosystem<\/strong><\/p>\n\n\n\n<p>The CloudSEK report emphasises that the current threat environment involves a wide spectrum of actors, ranging from sophisticated intelligence-linked groups to loosely coordinated hacktivists.<\/p>\n\n\n\n<p>At the highest tier are established Iranian advanced persistent threat (APT) groups such as APT33, APT34 (OilRig) and MuddyWater, which have long histories of targeting energy infrastructure, government agencies and telecommunications networks.<\/p>\n\n\n\n<p>These groups often conduct long-term infiltration campaigns designed to gain persistent access to strategic systems.<\/p>\n\n\n\n<p>Alongside them operate state-aligned or proxy groups like CyberAv3ngers and the Handala Hack Team, which have demonstrated capabilities in disruptive cyber operations including ransomware, wiper malware and infrastructure disruption claims.<\/p>\n\n\n\n<p>However, the most significant shift highlighted in the report is the sudden mobilisation of more than 60 hacktivist groups following the February 2026 escalation.<\/p>\n\n\n\n<p>These groups reportedly coordinated through Telegram channels referred to as an \u201cElectronic Operations Room.\u201d<\/p>\n\n\n\n<p>Unlike formal state units, such groups may lack discipline, operational oversight or technical sophistication.<\/p>\n\n\n\n<p>Yet they also face fewer constraints on targeting civilian infrastructure. According to the report, their access to modern AI tools may allow them to compensate for limited technical knowledge.<\/p>\n\n\n\n<p><strong>AI as a force multiplier<\/strong><\/p>\n\n\n\n<p>The CloudSEK report argues that Artificial Intelligence is transforming the early stages of cyber operations &#8211; not by inventing new attack techniques but by dramatically lowering the expertise required to conduct reconnaissance.<\/p>\n\n\n\n<p>Historically, attacking industrial control systems required specialised knowledge of industrial protocols, device configurations and operational technology networks.<\/p>\n\n\n\n<p>These systems often run proprietary protocols such as Modbus, DNP3 or PCOM and interacting with them required significant research and training.<\/p>\n\n\n\n<p><strong>AI tools now compress that learning process.<\/strong><\/p>\n\n\n\n<p>According to the report, an attacker can ask a large language model to generate queries that identify exposed industrial devices through search engines like Shodan.<\/p>\n\n\n\n<p>The same system can provide information on default credentials, explain device functions or help interpret web interfaces exposed by industrial hardware.<\/p>\n\n\n\n<p>In practical terms, the report notes, this means that an actor with minimal technical background can move from initial intent to a list of accessible infrastructure devices in minutes.<\/p>\n\n\n\n<p>The implication is not that AI creates entirely new cyber capabilities. Instead, it removes the research bottleneck that historically limited infrastructure attacks to a small number of skilled actors.<\/p>\n\n\n\n<p><strong>Evidence from real-world AI usage<\/strong><\/p>\n\n\n\n<p>Evidence of this trend has already appeared in earlier cyber campaigns.<\/p>\n\n\n\n<p>In October 2024, OpenAI released a threat intelligence report confirming that accounts associated with CyberAv3ngers had used ChatGPT during reconnaissance activities.<\/p>\n\n\n\n<p>The queries documented in that report included requests for:<\/p>\n\n\n\n<p>\u2022 Lists of industrial protocols and their associated network ports<br>\u2022 Default login credentials for industrial devices<br>\u2022 Guidance on interacting with industrial protocols such as Modbus<br>\u2022 Techniques for scanning networks for industrial systems<br>\u2022 Methods for obfuscating scripts used after compromise<\/p>\n\n\n\n<p>OpenAI assessed that these interactions did not reveal information beyond what could be found through traditional web searches.<\/p>\n\n\n\n<p>However, the CloudSEK report argues that this interpretation overlooks a key operational factor: speed.<\/p>\n\n\n\n<p>For a group reacting to a fast-moving geopolitical event, the ability to compress days of technical research into a single AI conversation can significantly accelerate operations.<\/p>\n\n\n\n<p><strong>The industrial attack surface problem<\/strong><\/p>\n\n\n\n<p>While AI lowers the barrier to reconnaissance, the CloudSEK report stresses that the larger problem lies in the growing exposure of industrial infrastructure systems on the public Internet.<\/p>\n\n\n\n<p>Operational technology devices &#8211; including PLCs, human-machine interfaces (HMIs) and industrial routers &#8211; are increasingly connected to external networks for monitoring and maintenance.<\/p>\n\n\n\n<p>In many cases, these systems remain accessible with minimal authentication or outdated security configurations.<\/p>\n\n\n\n<p>The report notes that exposure of industrial control systems increased significantly in recent years, with some industrial device ports seeing triple-digit percentage growth in Internet exposure despite repeated security advisories.<\/p>\n\n\n\n<p>In this environment, attackers often do not need sophisticated exploits.<\/p>\n\n\n\n<p>They only need to find devices that were never meant to be publicly accessible in the first place.<\/p>\n\n\n\n<p><strong>The Aliquippa case study<\/strong><\/p>\n\n\n\n<p>The Aliquippa water authority incident illustrates how these vulnerabilities can translate into real-world disruption.<\/p>\n\n\n\n<p>According to the CloudSEK report, the attack succeeded because a Unitronics PLC controlling part of the facility was accessible from the Internet and still used the manufacturer\u2019s default password.<\/p>\n\n\n\n<p>The attackers altered the system\u2019s display to show a political message, demonstrating control over the device.<\/p>\n\n\n\n<p>While the operational impact was limited, the event served as proof of concept.<\/p>\n\n\n\n<p>The report argues that the same method could be automated at scale.<\/p>\n\n\n\n<p>A simple script could search for Internet-exposed industrial devices, attempt known default credentials and log successful connections.<\/p>\n\n\n\n<p>With dozens of hacktivist groups potentially experimenting with such methods, the risk shifts from sophisticated sabotage to large-scale opportunistic scanning and disruption attempts.<\/p>\n\n\n\n<p><strong>AI platforms and the geopolitical context<\/strong><\/p>\n\n\n\n<p>The CloudSEK report also highlights how AI itself is becoming entangled in geopolitical dynamics.<\/p>\n\n\n\n<p>On the same day as the February 2026 military escalation, OpenAI announced a partnership with the US Department of Defense to provide AI capabilities for classified use.<\/p>\n\n\n\n<p>The announcement triggered significant public reaction, including spikes in uninstall rates and negative app reviews.<\/p>\n\n\n\n<p>Competing AI platforms experienced increased downloads as users reacted to the news.<\/p>\n\n\n\n<p>While the consumer backlash may appear unrelated to infrastructure security, the report argues that it reflects a broader issue: AI platforms are now deeply embedded in both sides of modern conflict.<\/p>\n\n\n\n<p>Governments increasingly rely on AI for intelligence and defence operations, while adversarial actors use similar tools for reconnaissance and attack planning.<\/p>\n\n\n\n<p>If major AI platforms restrict certain activities, malicious actors may simply migrate to less regulated or self-hosted systems.<\/p>\n\n\n\n<p><strong>Securing the Basics<\/strong><\/p>\n\n\n\n<p>Despite the complexity of the geopolitical context, the defensive measures highlighted in the report are relatively straightforward.<\/p>\n\n\n\n<p>Three basic security practices could have prevented the Aliquippa incident entirely:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Remove industrial management interfaces from direct Internet exposure.<\/li>\n\n\n\n<li>Replace default credentials before deploying industrial equipment.<\/li>\n\n\n\n<li>Block industrial protocol ports from external networks unless protected by secure gateways such as VPNs.<\/li>\n<\/ol>\n\n\n\n<p>These steps represent standard security hygiene rather than advanced defensive techniques.<\/p>\n\n\n\n<p><strong>A new cyber reality<\/strong><\/p>\n\n\n\n<p>The CloudSEK report concludes that the most significant shift in the cyber threat landscape is not technological sophistication but accessibility.<\/p>\n\n\n\n<p>The combination of AI-assisted reconnaissance, widespread infrastructure exposure and geopolitical motivation has created a situation in which infrastructure targeting is no longer limited to highly specialised actors.<\/p>\n\n\n\n<p>As the report puts it: \u201cthe barrier to ICS disruption is no longer technical &#8211; it is motivational.\u201d<\/p>\n\n\n\n<p>In an environment where dozens of ideologically motivated groups can mobilise within hours of a geopolitical event, the resilience of critical infrastructure may depend less on defeating advanced cyber weapons and more on closing the simple vulnerabilities that make such attacks possible.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new CloudSEK report warns that the convergence of Artificial Intelligence tools, expanding Internet-exposed industrial systems and ideologically motivated cyber actors is reshaping the threat landscape facing US critical infrastructure. In modern geopolitical conflict, cyber operations have increasingly become a parallel battlefield. A recent CloudSEK report, AI, the Iran-US Conflict and the Threat to US [&hellip;]<\/p>\n","protected":false},"author":58,"featured_media":52587,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16,17,10695,513,43,514],"tags":[10996,9407,10993,10998,6361,10995,10994,10991,10997,10992],"class_list":["post-52586","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-energy","category-enterprise-security","category-feature","category-regional-news-newsletter","category-top-stories","category-used","tag-ai-cyber-threats","tag-ai-cybersecurity","tag-cloudsek","tag-cyber-espionage-2","tag-cyber-warfare","tag-ics-security","tag-industrial-control-systems-security","tag-infrastructure-cyber-risk","tag-iran-us-cyber-conflict","tag-us-critical-infrastructure-security"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/52586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=52586"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/52586\/revisions"}],"predecessor-version":[{"id":52807,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/52586\/revisions\/52807"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/52587"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=52586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=52586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=52586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}