Situation report active Rev. 2026.9 119 reports 239 source records updated
Real Life After AGI Pengarahan kelangsungan hidup manusia
ID

AI-enabled cyberattacks on infrastructure

What AI is changing in cyber operations, why infrastructure is exposed, and why the offense-defense balance is uncertain, including a 2025 AI-espionage report.

Written by
Dwight Ringdahl
Status
Sumber diperiksa
Revised
Sources
4 cited
Reading
5 min
Belum tersedia dalam Bahasa Indonesia

Laporan ini belum diterjemahkan, sehingga naskah asli berbahasa Inggris ditampilkan di bawah. Lihat halaman metodologi untuk mengetahui cara cakupan terjemahan dilacak.

AI is already used in cyber operations

State-associated and criminal actors use general-purpose AI for reconnaissance, translation, scripting, phishing content, vulnerability analysis, and malware-related work. OpenAI and Microsoft reported such use by groups associated with China, Russia, Iran, and North Korea in 2024, while saying they had not identified a significant attack that was possible only because of their models (joint OpenAI–Microsoft disclosure).

In November 2025, Anthropic reported that a Chinese state-sponsored group used Claude Code in a cyberespionage campaign and attributed most tactical work to the model. Anthropic called it the first documented large-scale operation with minimal human intervention. That account is important company self-reporting, not an independently reconstructed public incident: sensitive details and telemetry are unavailable to outside researchers, and estimates of “80–90 percent” automation depend on how tasks are counted (Anthropic disclosure).

The 2026 International AI Safety Report reaches a calibrated conclusion: cyber capability is improving and attackers are adopting AI, but no fully automated end-to-end attack has been publicly reported and the effect on overall attack frequency remains unclear (International AI Safety Report 2026).

Where AI can change the workflow

A cyber operation is a chain, not a single prompt. Attackers identify targets, collect information, obtain access, move through networks, escalate privileges, evade detection, and pursue theft or disruption. AI can accelerate portions of this chain by searching large codebases, generating variants, translating technical material, or coordinating repetitive actions.

The most robust capability evidence concerns vulnerability discovery. AI systems have found real software flaws, and teams in DARPA’s AI Cyber Challenge used AI with conventional tools to analyze and patch open-source software (DARPA AIxCC). Discovery is dual use: a defender can patch a flaw, while an attacker can exploit it. Whether a result improves security depends on who finds it first, how disclosure is handled, and how quickly affected systems can update.

Agents may also lower skill and time requirements without creating novel expertise. A competent operator can delegate routine subtasks and operate at larger scale. A novice may receive plausible-looking code but lack the judgment to debug or conceal it. Benchmarks often use clean capture-the-flag exercises or known vulnerabilities, so high performance does not automatically transfer to a defended enterprise.

Why infrastructure deserves special attention

Electricity, water, communications, transportation, health systems, and financial clearing rely on interconnected digital and operational technology. Some equipment has long replacement cycles, limited logging, fragile availability requirements, or legacy protocols. Operators may be unable to install an ordinary patch without testing downtime and safety effects.

Still, “critical infrastructure” is not uniformly exposed. Some systems are segmented, use manual controls, or have strong sector-specific regulation. Many incidents begin with familiar weaknesses—stolen credentials, unpatched internet-facing systems, vendor access, poor backups, or social engineering—rather than an exotic AI-designed exploit. AI can intensify these routes, but basic security remains highly relevant.

Consequences also vary. A compromise of business email is different from control of physical equipment. Claims of a catastrophic infrastructure attack should explain the path from digital access to physical harm, the safety interlocks involved, and the attacker’s ability to maintain access. Avoiding that detail at a defensive level can turn a plausible scenario into an unsupported headline.

The offense-defense balance is unresolved

It is tempting to say attackers need to succeed once while defenders must succeed every time. That slogan captures one asymmetry but misses others. Defenders control architecture, identity, patching, monitoring, backups, and recovery. Defensive AI can inspect far more code and telemetry than human teams, prioritize alerts, find flaws before release, and automate remediation. Attackers must often remain covert, preserve access, and adapt to an environment they do not control.

The International AI Safety Report explicitly says it is unclear whether general-purpose AI will benefit attackers or defenders more. That uncertainty is the accurate forecast. Outcomes may differ by sector and time: offense may gain first from a new capability, followed by defense after tools and patches diffuse. Open-source components can spread both vulnerabilities and fixes rapidly.

AI systems also create new attack surfaces. Prompt injection can cause an agent to follow malicious instructions embedded in email, documents, or webpages. Excessive tool permissions can turn a model error into data loss. Model supply chains, plugins, memory stores, and credentials require the same least-privilege and isolation principles as other software—plus new testing for model-specific behavior.

What good evidence looks like

Cyber claims are difficult to attribute. A threat-intelligence company or AI developer sees only its own telemetry and may have commercial incentives. Victims may not disclose incidents. Attackers can use multiple models and conventional tools, making the marginal effect of AI hard to isolate.

Benchmarks can overstate capability through contamination or unrealistic scaffolding and understate it through poor elicitation. Reports should disclose the model version, agent tools, task novelty, human assistance, success criteria, repeated-trial rate, and whether the target was simulated or real. Independent reproduction and responsible disclosure add confidence.

Most importantly, separate observed adoption from causal impact. “An attacker used AI” does not prove that AI enabled the breach, increased damage, or changed the campaign’s outcome. At the same time, lack of public attribution does not prove absence. Confidence labels are more honest than categorical claims.

Defenses that work across capability scenarios

Infrastructure operators should inventory assets and dependencies, segment operational technology, require phishing-resistant multifactor authentication, minimize standing privileges, and monitor remote and vendor access. Tested offline backups and manual recovery procedures limit the impact of both AI-enabled attacks and ordinary ransomware. Procurement should require secure development and timely vulnerability handling.

AI agents need constrained permissions, isolated execution, logging, and human authorization for irreversible actions. Inputs from untrusted sources should be treated as hostile. Organizations should red-team prompt injection, credential leakage, and tool misuse before connecting agents to production systems.

Governments can support sector information sharing, minimum cybersecurity standards, coordinated disclosure, workforce development, and exercises that include physical recovery. Model developers can monitor abuse, preserve evidence, share indicators responsibly, and provide qualified external evaluators access to cyber-capability tests.

The calibrated conclusion

AI has crossed from hypothetical cyber relevance to documented use. It can automate meaningful parts of operations and improve vulnerability discovery. The strongest public evidence does not yet show fully autonomous end-to-end cyber campaigns, nor does it establish that offense will outpace defense for the foreseeable future.

The risk is serious because capability can scale, infrastructure contains persistent weaknesses, and agents can act faster than human review. The opportunity is equally concrete: the same systems can find and repair vulnerabilities. Policy should measure outcomes, harden systems, and preserve defensive access rather than treating a contested offense-defense balance as a settled law.

References

Summarized position

Anthropic reported that it assessed a Chinese state-linked group had used a jailbroken Claude Code to automate roughly 80–90% of a multi-target espionage campaign.

Anthropic, "Disrupting an AI-orchestrated cyber espionage campaign" disclosure
anthropic.com, Primary source
Summarized position

OpenAI reported disrupting accounts associated with five state-affiliated hacking groups that used its models for activities including reconnaissance and scripting support.

OpenAI, "Disrupting malicious uses of AI by state-affiliated threat actors" report, with Microsoft Threat Intelligence
openai.com, Primary source
  1. International AI Safety Report 2026 internationalaisafetyreport.org
  2. DARPA AIxCC aicyberchallenge.com

Type to search the manual.

navigate open esc close