Key Takeaways
- Former NSA hacker David Kennedy warns that frontier artificial‑intelligence models are dramatically lowering the technical barrier for cyber‑attacks, giving low‑skill actors capabilities once reserved for nation‑state groups.
- AI accelerates the discovery and exploitation of vulnerabilities, automates reconnaissance, and enables rapid, large‑scale campaigns that outpace traditional defenses.
- A wave of suspected cyber intrusions targeting U.S. water utilities has been reported across multiple states, raising alarms about the vulnerability of critical infrastructure.
- Attackers are using a mix of ransomware, credential stuffing, and supply‑chain compromises to disrupt treatment processes, steal operational data, and potentially threaten public health.
- Kennedy and cybersecurity experts urge increased federal‑state coordination, investment in AI‑driven defense tools, mandatory baseline security standards for water systems, and regular red‑team exercises to mitigate the growing threat.
Background on David Kennedy
David Kennedy is a former National Security Agency (NSA) hacker and the founder of TrustedSec, a cybersecurity consultancy that advises both private companies and government agencies on offensive and defensive security practices. His career spans penetration testing, threat intelligence, and incident response for high‑profile organizations, giving him a unique perspective on how emerging technologies reshape the threat landscape. On the program Varney & Co., Kennedy shared his insights on how artificial intelligence is reshaping hacking methodologies and why recent cyberattacks on water utilities should be viewed as a harbinger of broader risks to critical infrastructure.
AI as a Force Multiplier for Hackers
Kennedy explained that frontier AI models—large language models and specialized generative systems—are becoming powerful force multipliers for malicious actors. These models can ingest vast amounts of public code, vulnerability disclosures, and exploit kits, then synthesize novel attack vectors far faster than a human analyst could. By automating tasks such as network scanning, phishing crafting, and exploit development, AI reduces the time and expertise required to launch a sophisticated intrusion, effectively compressing the attack lifecycle from weeks or days to mere hours.
Lowering the Skill Barrier
One of Kennedy’s primary concerns is that AI democratizes elite hacking abilities. Traditionally, conducting a zero‑day exploit or evading intrusion detection systems required deep knowledge of operating systems, cryptography, and exploit development. Now, with AI‑assisted code generation and natural‑language prompting, a novice can describe a desired outcome—such as “bypass authentication on a SCADA system”—and receive functional exploit code or step‑by‑step instructions. This shift means that criminal gangs, hacktivists, and even hostile nation‑state proxies can field capabilities previously limited to well‑funded advanced persistent threat (APT) groups.
Speed and Scale of Threats
Beyond lowering entry barriers, AI amplifies the speed and scale of cyber campaigns. Automated reconnaissance can continuously probe thousands of IP addresses, identifying misconfigurations or unpatched services in real time. When a vulnerability is found, AI‑driven exploit generation can produce a working payload within minutes, enabling attackers to launch widespread campaigns before defenders can patch or detect the activity. Kennedy noted that this tempo creates a “defender’s dilemma”: security teams must operate at machine speed to keep up, necessitating AI‑based detection and response tools of their own.
Recent Water Utility Cyberattacks Overview
Kennedy turned to the specific wave of suspected cyberattacks on U.S. water utilities that have been reported across several states. These incidents, highlighted on Varney & Co., involve unauthorized access to supervisory control and data acquisition (SCADA) networks, ransomware deployment, and data exfiltration of customer information and operational schematics. While many attacks have been thwarted before causing service disruption, the pattern indicates a growing interest in targeting essential services that directly affect public health and safety.
State‑Level Reports and Examples
According to state cybersecurity agencies cited in the segment, at least fifteen states have filed incident reports related to water system intrusions over the past six months. Notable examples include a ransomware attack on a municipal water treatment plant in California that temporarily disabled chemical dosing controls, a credential‑stuffing campaign against a Texas utility that exposed employee login databases, and a spear‑phishing effort targeting a Florida utility’s SCADA administrators that attempted to manipulate pump frequencies. Though none of these incidents resulted in catastrophic failure, they demonstrated that attackers can reach critical control layers with relative ease.
Attack Vectors and Tactics
Kennedy detailed the common tactics observed in these water‑utility breaches. Initial access frequently came through phishing emails that delivered malicious links or attachments, exploiting human fatigue in utilities that often lack dedicated security awareness training. Once inside, attackers used lateral movement techniques such as Pass‑the‑Hash and exploited outdated remote‑desktop protocols to reach OT (operational technology) networks. In several cases, ransomware payloads were deployed that encrypted both IT and OT files, threatening to shut down treatment processes unless a ransom was paid. Additionally, some intruders attempted to exfiltrate hydraulic models and chemical dosing formulas, which could be repurposed for future sabotage or sold on underground markets.
Implications for Critical Infrastructure
The water sector’s vulnerability underscores a broader challenge for all critical infrastructure: the convergence of IT and OT environments expands the attack surface while many utilities operate on legacy systems that lack modern security controls. Kennedy warned that successful disruption of water treatment could lead to contaminated supplies, service outages, and loss of public trust, with potential cascading effects on hospitals, fire services, and food production. Moreover, the low cost and high impact of such attacks make them attractive to adversaries seeking to exert pressure without invoking conventional military responses.
Policy and Defensive Recommendations
To counter the AI‑enhanced threat landscape, Kennedy advocated a multi‑layered strategy. First, he called for mandatory baseline cybersecurity standards for water utilities, including network segmentation between IT and OT, multi‑factor authentication for remote access, and regular patch management for legacy systems. Second, he recommended increased investment in AI‑driven defense tools—such as anomaly detection models that learn normal OT traffic patterns and flag deviations indicative of manipulation. Third, he stressed the importance of information‑sharing hubs that enable real‑time threat intelligence exchange between state agencies, federal partners (CISA, FBI), and private‑sector ISACs. Finally, Kennedy urged utilities to conduct frequent red‑team and purple‑team exercises that simulate AI‑generated attack scenarios, ensuring that response teams can operate effectively under machine‑speed pressure.
Conclusion
The insights shared by former NSA hacker David Kennedy on Varney & Co. illuminate a troubling trend: artificial intelligence is rapidly transforming the cyber threat landscape by empowering low‑skill actors with elite capabilities and accelerating the tempo of attacks. The concurrent rise in cyber intrusions targeting U.S. water utilities serves as a concrete illustration of how these trends threaten essential services that millions rely upon daily. Addressing this challenge will require coordinated policy action, modernization of defensive technologies, and a cultural shift toward proactive, AI‑aware cybersecurity hygiene across the critical‑infrastructure sector. Without such measures, the gap between offensive innovation and defensive readiness will continue to widen, leaving vital public services increasingly exposed to disruptive and potentially harmful cyber campaigns.

