Energy Companies Face More AI-Enhanced Cyberattacks as Power Systems Become More Connected

01 Event

Energy companies are facing a growing wave of cyberattacks in which artificial intelligence is being used to make attacks faster, easier to automate and more scalable. Reuters reported that increasingly digitalized networks across power generation, transmission and distribution have created a larger attack surface for hackers.

The threat is not limited to office computers. Security researchers say attackers are targeting operational technology, including programmable logic controllers and substations that help control power generation and electricity flows.

AI is being used to write attack scripts, analyze large amounts of information and identify vulnerable targets. That can reduce the level of specialist knowledge needed to carry out parts of an attack.

02 What Changed?

Industrial cyberattacks are not new, but two things are changing at the same time. Energy systems are becoming more connected, while large language models and other AI tools make certain technical tasks easier to automate.

Reuters cited Rob Denaburg of the American Public Power Association, which represents 1,400 community-owned public power utilities in the United States, saying large language models can automate a large percentage of a typical attack path and lower the resources, time and expertise required.

Researchers also described AI-generated social-engineering material and scripts designed to communicate with industrial protocols. That matters because operational technology uses specialized systems that historically required deeper engineering knowledge to attack effectively.

This follows the broader trend Earnyx covered in more than 100 companies warning about AI-enabled cyberattacks and the recent Hugging Face attack involving rogue AI agents.

03 Why It Matters

Cyberattacks against energy infrastructure can create consequences that extend beyond stolen data. Power systems support hospitals, transport, communications, businesses and households. Disrupting an industrial control system can therefore become a physical-service problem.

Reuters noted that Ukraine’s energy infrastructure has been repeatedly targeted by Russian hackers and that Poland faced an attack in December aimed at disrupting communications between renewable-energy installations and distribution operators. U.S. officials also warned in August about attempts to breach Siemens devices used across critical infrastructure sectors.

The United Kingdom briefed energy-company executives on defensive steps after reports that Iran-linked hackers had shut down a small British energy facility. UK officials said there was no threat to the wider electricity system.

04 What It Means for You

For consumers, the main implication is resilience. People cannot personally secure a power station, but the security of utilities affects the reliability of services they depend on every day.

For businesses operating critical infrastructure, AI changes the economics of defense. An attacker may use automation to probe many targets quickly, while defenders need to protect systems consistently. Smaller utilities can be particularly exposed because they may have fewer cybersecurity staff and older equipment.

That does not mean AI only helps attackers. Utilities and security teams can also use AI to analyze logs, prioritize vulnerabilities and detect suspicious behavior. The advantage depends on how responsibly and effectively each side applies the tools.

05 Numbers + Context

The American Public Power Association represents about 1,400 community-owned, not-for-profit public power utilities. Reuters cited experts from organizations including Dragos, Bridewell and the association to describe how AI is changing attack methods.

Researchers said Russian-aligned group RomCom very likely used AI to create social-engineering content targeting UK critical-national-infrastructure organizations in 2025. Security experts also described Iranian-aligned actors using AI-generated scripts against operational-technology assets.

The important number is not a single global attack count. The broader pattern is that more connected devices and software create more possible entry points, while AI can reduce the effort needed to search for weaknesses.

06 Earnyx Takeaway

AI does not magically turn every hacker into an industrial-control expert, but it can lower some of the barriers that once slowed attackers down. That matters when the targets are power grids and energy facilities rather than ordinary websites.

The practical response is not to disconnect modern energy systems from technology. It is to treat cybersecurity as core infrastructure maintenance: inventory connected assets, patch known weaknesses, segment critical systems, monitor unusual behavior and give smaller utilities access to the same defensive expertise larger operators can afford.

The risk also argues for separating convenience from necessity. More connectivity can improve monitoring and efficiency, but every added connection should have a clear operational purpose and appropriate controls. In critical infrastructure, the value of a new digital capability has to be weighed against the additional attack surface it creates. That cost-benefit test becomes more important as AI lowers the effort required to scan, automate and adapt attacks.

Source: Reuters, September 1, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *