Cyber Strategy

Even Before Mythos, American Critical Infrastructure Faced Significant Cyber Risks

August 20, 2026
QUICK SUMMARY

U.S. operational technology (OT) and critical infrastructure (CI) face growing cyber threats as advances in AI introduce new risks to an already complex landscape. This article explores key vulnerabilities and recommendations for strengthening OT/CI security, emphasizing that preparing for AI-enabled threats starts with getting cybersecurity fundamentals right.

Why strengthening OT cybersecurity matters even more in the age of AI

Introduction

July 2026 was not a great month for those concerned by the vulnerability of U.S. critical infrastructure (CI) to cyberattacks.

First, two major AI labs reported that advanced models exceeded the intended boundaries of isolated testing environments and infiltrated other companies’ production environments without permission. Then, attackers hacked into organizations in the water and wastewater sectors in multiple states and disrupted operations. CyberAv3ngers, a group aligned with Iran, has taken credit for the attacks.

U.S. critical infrastructure faces a growing range of cyber-physical threats, and improving operational technology (OT) cybersecurity rapidly and effectively requires widespread cooperation and coordination.

This article highlights significant cyber threats to OT and CI systems, identifies key vulnerabilities in them, and offers recommendations for hardening and defending these systems in our AI-focused age.

This is vital because attacks that degrade the operation of water treatment plants, hospitals, or electric substations not only impact computer systems and networks: people can die.

A disrupted water supply might mean that bottled water must quickly be supplied to a population, and it also severely impacts hospital operations. Cyber defense here is, literally, defending as if lives depended on it.

Significant Vulnerabilities and Threats in the OT/CI World

OT environments are ones in which system availability and the safe operation of physical processes are top priorities. For this reason, some OT systems use legacy hardware and software, which may no longer be vendor supported (no more software or firmware updates). Unless such systems are effectively isolated from the internet and internet-connected systems, they remain particularly vulnerable to exploitation by adversaries. Even systems that can be patched regularly are often not because shutting down operations for updates can be costly and dangerous.

Gaps in foundational security practices can also pose problems. Examples include the failure to change vendor pre-set (default) passwords, the use of weak password policies (such as requiring fewer than 12 characters or allowing dictionary words), and the posting of passwords on sticky notes or in visible areas. Failure to effectively isolate critical systems following the Purdue Model or OT cybersecurity guidance in NIST 800-82 and a lack of full visibility into system operations (knowing what is connected to what) pose additional risks.

Two significant threats to OT operations come from adversarial nation-state hackers and cybercriminals. The former are aligned with and often financially-supported by nations in conflict or competition with the United States, militarily or economically. These nations include Russia, North Korea, China, and Iran. Major goals include damage, disruption, data theft, and espionage. Cybercriminals may or may not be nation-state-aligned and have financial gain as a primary motive.

Ransomware attacks are commonly used by them, in which systems and data are held hostage through encryption until a ransom is paid to the attackers, as in the 2021 Colonial Pipeline incident. With Colonial Pipeline, a ransomware attack led to physical consequences as fuel supplies were disrupted when the company shut down the pipeline system as a precautionary measure.

How AI is Changing the Threat Landscape

Recent advances in AI capabilities add to the urgency of protecting OT and CI systems from cyberattacks. ChatGPT was released almost four years ago, but now the most advanced frontier models from OpenAI and Anthropic can detect security vulnerabilities in software and systems and develop exploits for them at a scale and speed unimaginable even a year ago. If these tools can help secure systems and software, attackers can also use them to carry out cyberattacks of great complexity rapidly and on a large scale.

Three points are worth noting here:

  • Recent events have shown that advanced AI models can behave in unexpected ways and exceed the intended boundaries of controlled testing environments
  • The development of AI world models will significantly escalate threats to OT and CI systems
  • AI-enabled attacks should not be your first concern, if your basic cyber hygiene and posture are insufficient.

In July 2026 both OpenAI and Anthropic reported incidents in which advanced models they had developed moved outside of test environments that were supposed to be isolated, reached the public internet, and accessed other companies’ production systems without authorization.

The OpenAI incident involved agents escaping a testing environment intended to be isolated and breaching the open-source machine learning model and AI dataset platform Hugging Face to find solutions to an evaluation task.

The Anthropic incident involved a misunderstanding between Anthropic and a third-party evaluation partner about whether Claude would have internet access during testing.

Both incidents reveal how AI tools are rapidly advancing in capabilities and how they can resort to unexpected behaviors to achieve their goals.

A particular threat to OT environments could be the use of AI world models to assist in attacks. World models are trained on visual data so that they develop a deep understanding of our physical world and can predict future states of physical environments. Important uses include in training autonomous driving systems, in robotics, and in industrial systems for advanced modeling tasks.

Such modeling could also be used to supercharge cyberattacks in OT environments. Models trained on industrial process data could give attackers enough knowledge of system architectures, potentially enabling them to cause specific targeted physical effects without requiring insider knowledge or extensive reconnaissance.

In the end, however, AI-assisted attacks should not be your first concern if your basic cybersecurity practices are substandard.

If your critical systems are not patched with the latest security updates, are not properly isolated from systems that connect to the internet, or if your password and authentication/authorization policies are weak, attackers may be able to compromise you with or without AI assistance. But if your critical systems are properly updated and isolated, even AI-enabled attackers will find it difficult to break in.

While AI-enabled threats deserve attention, they should not be a distraction from cybersecurity fundamentals. Your first priority is to make sure that you follow basic cyber best-practices.

Additional Recommendations

At the policy level, urge Congress and the Executive Branch to increase funding for the Cybersecurity and Infrastructure Security Administration (CISA) and for public-sector CI organizations. Congress should also extend the Cybersecurity Information Sharing Act of 2015 (CISA 2015) to enable continued transparent information sharing between critical infrastructure organizations and the government. Without CISA 2015’s legal protections, companies are less likely to share information related to cyber incidents because of concerns about potential legal liability and regulatory consequences.

Additionally:

  • Government should consider implementing Zero-Knowledge Proofs, which enable organizations to share information without revealing proprietary information or system designs that could be used against them in a cyberattack
  • Cyber insurers should require a cyber safety standard of care as a condition of coverage, showing that cyber safety and design best practices are built into an organization’s networked systems
  • OT systems and their authentication procedures should be designed for ease of use by operators, many of whom are not cybersecurity experts
  • OT practitioners, cybersecurity experts, and those in government often have very different levels of technical understanding and vocabulary. We need unified terminology and definitions, as well as clear, jargon-free communications between these groups.

Improving our OT cybersecurity in the age of AI-assisted threats requires nonpartisan cooperation and accurate attribution of cyberattacks, funding to staff agencies like CISA and address vulnerabilities, and clear communications to enable rapid information sharing and coordination among various stakeholders.


Are you ready to take the next step in your cybersecurity journey?

The Cyber Guild connects leaders, practitioners, and emerging talent through events, mentorship, and community.

👉 Explore upcoming events
👉 Subscribe to our mailing list
👉 Learn more about RISE Mentorship

Stephen Thursby
ABOUT THE AUTHOR
Stephen Thursby

Stephen Thursby is a cybersecurity policy analyst who recently completed an internship in the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies. He holds a Ph.D. in Musicology and Security+ certification. His areas of focus include AI governance and operational technology cybersecurity policy. Stephen also volunteers with The Cyber Guild, the Cybersecurity Canon project, and the Maryland Center for Critical Infrastructure Security. He is eager to contribute his research, writing, analysis, and communications skills in a full-time role with an organization focused on public policy, education, or OT cybersecurity.Â