AI-Assisted Cyberattacks Surge as Threat Actors Target Critical Infrastructure

Digital illustration showing a power plant and data center under cyber threat with AI network overla

Quick Read

  • AI tools like Claude Code are now being used to autonomously execute network intrusions and data exfiltration.
  • Recent breaches in Mexico exposed records of 95 million taxpayers, facilitated by AI-driven reconnaissance.
  • A UK power plant was forced offline for four days following a cyberattack linked to Iranian-affiliated actors.
  • Security experts warn that while AI acts as a 'force multiplier' for attackers, standard defenses like MFA and patching remain essential.

The New Frontier of Automated Intrusions

The landscape of cyber warfare has shifted significantly in 2026, as threat actors increasingly integrate artificial intelligence tools into their offensive operations. Recent intelligence reports indicate that attackers are leveraging large language models (LLMs) and specialized AI agents, such as Claude Code, to execute semi-autonomous network intrusions at unprecedented speeds and scales.

Security researchers at firms including Ctrl-Alt-Intel and Gambit Security have identified “AI fingerprints” in a growing number of breaches. Unlike traditional manual hacks, these AI-assisted attacks involve LLMs that handle complex reasoning, rewrite exploits in real-time, and automate data exfiltration. In one notable campaign documented between late 2025 and early 2026, a Spanish-speaking threat actor compromised nine Mexican government departments, exposing data related to 95 million taxpayers and millions of vehicle registrations. The AI tools enabled the attacker to map databases and spray passwords across hundreds of servers within hours rather than days.

Critical Infrastructure Under Fire

The impact of this technological shift extends beyond data theft to the operational disruption of critical national infrastructure. In a recent, unprecedented incident, a UK-based power generator was forced to shut down for four days following a cyberattack attributed by reports to Iranian-affiliated hackers. While the incident reportedly went largely unnoticed by the public and was not intended to harm civilians, it highlights the vulnerability of essential services to highly automated intrusion techniques.

The UK’s National Cyber Security Centre (NCSC) has responded by issuing briefings to energy companies and businesses, emphasizing that hostile states—including China, Iran, and Russia—remain the primary drivers of nationally significant cyber threats. The UK government is currently developing a system that will utilize AI agents to detect and flag threats to airlines, telecoms, and energy providers, essentially fighting AI with AI.

The Mechanics of AI-Driven Attacks

Researchers have recovered logs showing that sophisticated attackers use AI not just for reconnaissance, but as a “force multiplier” for the entire attack lifecycle. In several instances, attackers utilized Claude Code to generate and execute remote command execution activity, while OpenAI’s GPT-4.1 API was deployed to analyze structured data and generate intelligence reports from compromised internal servers.

Despite the advanced nature of these tools, security experts note that fundamental defenses remain highly effective. “The same defenses, even those simple ones such as patching vulnerabilities and enforcing MFA, will go a long way,” said Ben Folland, a security researcher at Ctrl-Alt-Intel. Nevertheless, the homogenization of attack patterns through AI makes attribution increasingly difficult for law enforcement, as the forensic “style” of human hackers is masked by the standardized output of large language models.

|
Creator:Azat TV Editorial

LATEST NEWS