AI systems are fully capable of carrying out nightmare attacks against infrastructure and nobody's ready
Meanwhile, AI agents move robotic arms, 'make OT device operator screens lie'
A Booz Allen Hamilton report reveals that autonomous AI systems are fully capable of carrying out nightmare cyberattacks against critical infrastructure, such as water, power, and other daily necessities. The consulting firm's OT lab tested eight scenarios to examine advanced models' capabilities within an autonomous, AI-enabled OT attack chain.
The tests showed that AI agents could operate with speed, persistence, and engineering-level precision, potentially outpacing organizations with inadequate OT cybersecurity practices. Kyle Miller, VP of infrastructure cybersecurity at Booz Allen, stated that while there is no defined timeline for a nightmare scenario, the growing use of AI in real-world attacks and increasing model capabilities raise the risk exponentially.
The tests used a multi-vendor environment modeled after a general manufacturing facility, including programmable logic controllers, human-machine interfaces, SCADA platforms, and other physical equipment. The AI models were able to map the environment, identify critical assets, find vulnerabilities, move into systems running production, manipulate controller brands, change motor frequency or speed, compromise SCADA, alter operator screens, control connected equipment, and even make a robotic arm move.
The findings suggest that less-skilled attackers can exploit weaknesses in industrial systems, as specialized OT knowledge and complex control environments are no longer barriers to attack.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.