Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

AI systems capable of 'nightmare' attacks on critical infrastructure

Autonomous AI systems can find and attack critical operational technology, potentially shutting down access to essential services, according to a Booz Allen Hamilton report.

  • AI models achieved objectives across eight test scenarios, turning digital access into physical actions.
  • In one test, AI models progressed from a perimeter compromise to actions inside an industrial control network in just over 16 minutes.
  • The models performed OT-focused tasks with a high degree of engineering-level precision, identifying equipment and altering process values.

Autonomous AI systems are capable of carrying out cyberattacks that could disrupt critical operational technology (OT) and industrial equipment, potentially cutting off access to water, power, and other daily necessities. A report by consulting firm Booz Allen Hamilton indicates that defenders may have only minutes to detect and block such attacks.

Booz Allen's OT lab tested eight scenarios using advanced AI models within an autonomous, AI-enabled attack chain. The models successfully achieved their objectives in all scenarios, translating digital access into physical actions. This included finding and moving a robotic arm in minutes and progressing from a perimeter compromise to actions within an industrial control network in just over 16 minutes.

Kyle Miller, VP of infrastructure cybersecurity at Booz Allen, stated that testing showed AI agents can operate with speed, persistence, and engineering-level precision that may outpace organisations without foundational OT cybersecurity practices. The firm declined to name the specific models tested, describing them as two of the "latest frontier models from the leading AI providers."

The tests revealed that AI agents could map environments, identify critical assets, find security vulnerabilities, and exploit multiple weaknesses to gain access to production systems. They were also able to manipulate various controller brands, change motor frequencies, compromise SCADA systems to alter operator screens, and control connected equipment, including a robotic arm.

The report suggests that specialised OT knowledge and complex control environments are no longer significant barriers to attack, as AI agents can learn about these systems. Many OT devices also lack authentication or encryption, making it easier for autonomous agents to execute malicious commands once a breach occurs.

Why this matters: The findings suggest that less-skilled attackers could potentially cause physical disruption to industrial systems by leveraging AI, as the technology can overcome the traditional barriers of obscure protocols and proprietary hardware.

What this means for you: If such attacks were to occur, they could disrupt essential services like water and power, impacting daily life.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.