AI-Generated Exploits Used in Ongoing Attacks on U.S. Critical Infrastructure

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

U.S. federal agencies have warned of active cyberattacks targeting Siemens S7 programmable logic controllers in critical infrastructure sectors. Hackers are leveraging AI-generated exploitation scripts to compromise systems in energy, water, manufacturing, and other industries, risking operational disruption, safety incidents, and equipment damage across the United States.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event explicitly involves AI systems used by hackers to facilitate cyberattacks on critical infrastructure, which has already resulted in harm or disruption. The AI is used to create malicious code that enables unauthorized access and control over industrial control systems, directly linking AI use to harm to critical infrastructure (harm category b). This meets the definition of an AI Incident because the AI system's use has directly led to significant harm and disruption. The event is not merely a potential risk or a complementary update but an active, ongoing incident involving AI-enabled harm.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Energy, raw materials, and utilitiesMobility and autonomous vehicles

Affected stakeholders
BusinessGeneral public

Harm types
Public interestEconomic/PropertyPhysical (injury)

AI system task:
Content generation


Articles about this incident or hazard