HomeSecurityCyberattacks and energy: Man remains the biggest threat

Cyberattacks and energy: Man remains the biggest threat

Cyberattacks on critical energy infrastructure are one of the most significant risks of our time, and according to experts, the biggest threat comes not from “autonomous” artificial intelligence, but from people exploiting new AI tools for malicious purposes. The situation in the energy sector is particularly worrying, as the systems that control electrical grids, pipelines and power generation facilities often rely on outdated technology with serious security gaps. The need for immediate action is imperative, before attackers fully exploit the possibilities offered by Generative AI.

cyberattacks on energy infrastructure AI threat security

In recent years, the number of cyberattacks against energy infrastructure has increased dramatically globally. Incidents such as the 2021 , attack ransomware Colonial Pipeline which led to fuel shortages across much of the eastern US, or the attack on the Ukrainian power grid in 2015 and 2016 , demonstrate that the consequences of such attacks can be devastating for millions of citizens. In this context, the emergence of generative AI tools adds a new dimension to the threat landscape.

Cybersecurity experts, such as Josh Corman, one of the most well-known critical infrastructure analysts, emphasize that the real threat is not “rogue” artificial intelligence acting autonomously, but malicious people using AI to accelerate and optimize their attacks. The speed with which attackers can now act has increased significantly, in many cases surpassing the ability of defenders to respond effectively.

See also: Cybersecurity Act 2: What changes for the security of the ICT supply chain in the EU and Greece

Cyberattacks on energy infrastructure: How AI is changing the game

The integration of artificial intelligence into cybercriminals’ arsenal has fundamentally changed the way attacks are planned and executed. tools Generative AI allow attackers to create sophisticated phishing messages in dozens of languages, automatically analyze code to discover zero-day vulnerabilities, and adapt their tactics in real time. This means that even attackers with limited technical knowledge can now execute sophisticated attacks against critical infrastructure.

One of the most worrying scenarios involves the use of AI to automate target recognition ( reconnaissance ). Attackers can use models machine learning to analyze publicly available information about energy facilities, identify weak points in their network architecture, and plan targeted attacks with much greater efficiency than in the past. At the same time, the creation of deepfake content for social engineering attacks is a growing threat to personnel working in critical facilities.

Cyberattacks and energy: Man remains the biggest threat

The situation is made worse by the fact that many energy infrastructure control systems — known as ICS (Industrial Control Systems) and SCADA (Supervisory Control and Data Acquisition) — were designed decades ago, at a time when cybersecurity was not a priority. Integrating these outdated systems with modern networking technologies creates a dangerous mix of vulnerabilities that attackers can exploit.

Cyberattacks on energy infrastructure: The human factor

Despite technological advances, the human factor remains the most critical variable in the cybersecurity equation. According to research, over 80 % of successful cyberattacks begin with some form of social engineering — typically a phishing email that tricks an employee into revealing credentials or executing malware. This means that even the most sophisticated technical security measures can be bypassed by a single human error.

See also: FBI Kinetic Cyber ​​Range: Fake city for cyberattack training

State actors — particularly groups affiliated with countries like Russia, China, North Korea , and Iran — pose the most serious threat to energy infrastructure worldwide. Groups like Sandworm (attributed to the Russian military intelligence agency GRU) have demonstrated their ability to infiltrate critical networks and cause actual power outages. The use of AI by these groups is expected to further enhance their capabilities.

It is worth noting that the threat is not limited to state actors. Ransomware such as BlackCat/ALPHV and LockBit have repeatedly targeted energy companies, recognizing that the criticality of the services they provide makes them more likely to pay ransoms. The integration of AI into these groups’ operations is expected to make their attacks even more sophisticated and difficult to counter.

cyberattacks on energy infrastructure - SecNews.gr

To address these threats, experts like Corman recommend a holistic approach that combines technology upgrades, staff training, and developing robust incident response strategies. Specifically, it is suggested replacing outdated SCADA systems with modern solutions that incorporate cybersecurity principles from the beginning (security by design), implementing the principle of least privilegetolimit access to critical systems, and regularly conducting cyberattack simulation exercises (red team exercises).

In the European context, the NIS2 (Network and Information Security Directive 2) directive , which entered into force in 2023, imposes stricter cybersecurity requirements for organizations managing critical infrastructures , including energy infrastructures. Greece, as a member of the EU , is obliged to implement these requirements, which is expected to improve the security level of Greek energy infrastructures. However, implementation remains a challenge, especially for smaller organizations that lack the necessary resources.

See also: WordPress: Critical vulnerability in Elementor Pro is used in cyberattacks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

According to The Verge, the debate over the role of artificial intelligence in the cybersecurity of critical infrastructure is at the center of interest among experts and policymakers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS