Industrial cybersecurity firm Dragos has warned that large language models (LLMs) from OpenAI and Anthropic — the class of AI systems behind ChatGPT and Claude — were used in a cyber-attack against critical infrastructure, according to a report published by Infosecurity Magazine on May 6, 2026. The disclosure places frontier AI tools directly inside an attack on the operational technology (OT) world: the industrial control systems that run power grids, water treatment, pipelines, and manufacturing.
Executive Summary
According to the report, Dragos — one of the best-known specialists in securing industrial control systems — says commercial frontier LLMs were used in the course of an attack on critical infrastructure. If borne out in detail, this would be among the first publicly flagged cases tying named frontier-model providers to a real-world intrusion in the OT domain, rather than in ordinary IT networks.
The significance is less about any single incident and more about the trajectory it confirms: general-purpose AI assistants can compress the time, skill, and cost required to research targets, write malicious tooling, and navigate unfamiliar industrial environments. For operators of data centers, utilities, and connectivity infrastructure, the warning is a signal that AI-assisted adversaries should now be part of baseline threat modeling — while readers should also note that, at headline level, the report leaves the technical specifics of how the models were used unconfirmed.
AI Lowers the Barrier to Industrial Attacks
Attacks on operational technology have historically demanded rare expertise: knowledge of protocols like Modbus and DNP3, familiarity with vendor-specific controllers, and patience to map physical processes. That scarcity of skill has been an unofficial defense. LLMs erode it. A capable general-purpose model can explain an unfamiliar protocol, draft scripts, translate documentation, and troubleshoot errors on demand — for an attacker as readily as for an engineer.
That is why a warning from Dragos specifically matters. The firm’s entire focus is the OT threat landscape, and its naming of frontier models signals that AI-assisted tradecraft has crossed from IT espionage — where AI-enabled campaigns had already been documented by the model providers themselves — into the systems that keep physical infrastructure running.
What “LLMs Used in an Attack” Can Actually Mean
The phrase covers a wide spectrum, and the distinction matters enormously. At the mild end, attackers use AI for reconnaissance, phishing text, or code assistance — an efficiency gain, not a new capability. At the severe end, models orchestrate portions of an intrusion with limited human input, a pattern Anthropic itself publicly documented in late 2025 when it disclosed disrupting a state-linked campaign that abused its Claude models for largely automated espionage.
The headline-level report does not establish where on that spectrum this incident sits, whether provider safeguards were bypassed (for example through jailbreaking or posing as legitimate security testers), or whether the models materially changed the outcome versus merely accelerating it. Readers should hold that uncertainty: “AI was used” is not yet “AI was decisive.” Equally, the involvement of a provider’s model in an attack is not evidence of negligence by that provider — every widely available tool, from scanners to cloud accounts, gets abused.
The Defender’s Dilemma — and the Vendor Lens
For infrastructure operators, the practical implications are concrete. AI-assisted attackers iterate faster, so detection and response windows shrink. The fundamentals become more valuable, not less: segmenting OT networks from IT, monitoring industrial protocols for anomalies, controlling remote access, and rehearsing manual-operation fallbacks. Defenders are also adopting AI for log triage and anomaly detection, setting up a genuine capability race on both sides of the wire.
Fair scrutiny cuts in both directions. Dragos sells OT security products and services, so dramatic warnings align with its commercial interests — a reason to ask for technical specifics, not a reason to dismiss the claim. The firm has a long track record of credible, evidence-based industrial threat reporting, and the warning is consistent with disclosures the AI providers themselves have made about abuse of their models. The right posture is to treat the claim as plausible and important, and to press for the incident details that would let operators act on it.
Background
Dragos was founded in 2016 by former U.S. intelligence-community analysts, including CEO Robert M. Lee, and has built its reputation on tracking threat groups that target industrial control systems — publishing widely cited analyses of incidents like the attacks on Ukraine’s power grid. Its warnings carry unusual weight in the OT security community precisely because the firm rarely deals in hypotheticals.
The AI-abuse backdrop was already forming before this report: through 2024 and 2025, OpenAI and Anthropic each published threat-intelligence reports documenting state-linked and criminal actors misusing their models, and in November 2025 Anthropic disclosed disrupting an espionage campaign in which its Claude models automated substantial portions of intrusion work. The Dragos warning, as reported on May 6, 2026, marks the extension of that trend to the critical-infrastructure domain.