Application security, AI/ML, Critical Infrastructure Security, Government security

US cyber officials warn AI is giving attackers an edge

CISA Acting Director Nick Andersen

Federal cyber officials warned that artificial intelligence is currently giving attackers an advantage over defenders, as the U.S. government confronts persistent Chinese cyber campaigns targeting telecommunications and other critical infrastructure.

Speaking during an Institute for Critical Infrastructure Technology (ICIT) panel on June 10, 2026, on cyber incident response and interagency coordination, FBI Cyber Division Assistant Director Brett Leatherman and CISA Acting Executive Director Nick Andersen said agencies are working more closely with industry and each other to counter increasingly sophisticated threats.

Leatherman described Salt Typhoon, a Chinese state-sponsored cyberespionage campaign targeting telecommunications companies, as the most consequential cyberespionage operation the U.S. has faced. The FBI was tipped off to suspicious Chinese activity by Microsoft in mid-2024 and later identified targeting of U.S. telecommunications providers, he said.

At least 10 U.S. telecommunications providers were identified as victims, while the government notified 80 other countries about related activity.

Leatherman said about 110 people, including senior U.S. government officials, were notified that their voice or text communications had been targeted and likely collected. The operation targeted telecommunications infrastructure rather than individuals' devices, making mitigation more difficult.

Officials said the campaign's effects are still being addressed. While affected providers are believed to have contained the attackers, Leatherman said there was no confirmation they had been fully eradicated from telecommunications infrastructure.

The officials also pointed to vulnerabilities in internet-facing and aging technology as an escalating concern. Andersen said CISA is prioritizing remediation based on factors, including whether vulnerabilities are actively exploited, remotely accessible or easily automated.

AI could accelerate that threat. Leatherman predicted attackers will increasingly exploit edge devices at scale with the technology, while Andersen warned critical infrastructure operators should expect persistent attempts by malicious actors to gain footholds in their systems.

At the same time, the agencies are exploring AI for defense. Leatherman said the FBI sees potential uses including analyzing large datasets, identifying adversary infrastructure and helping incident-response teams locate malicious activity more quickly. He said human oversight would remain necessary when AI is used to analyze information connected to court-authorized investigations.

Both officials said AI currently favors attackers because adversaries can adopt it faster and without the safeguards imposed on government and industry.

The challenge, Leatherman said, is to shift that advantage toward defenders while deploying AI responsibly and quickly.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds