Key Takeaways
- State and local governments are now the most targeted entities for cyber‑espionage, especially by China, which seeks to position itself to disrupt critical services in a potential Taiwan conflict.
- Attackers are no longer limited to ransomware; they are infiltrating water, power, transportation, and supplier networks to lie in wait for strategic escalation.
- Many local utilities still run outdated, unpatchable software, making them easy prey compared to hardened private‑sector utilities.
- Iran’s cyber activity, while less sophisticated, exploits the same low‑hanging fruit—default passwords and legacy systems—to cause immediate disruption.
- AI is transforming the threat landscape by automating the entire attack chain, from vulnerability discovery to ransom negotiations, and by enabling rapid identification of previously unknown zero‑day flaws.
- The emergence of AI models like Anthropic’s Mythos that can uncover decades‑old vulnerabilities lowers the barrier to entry for attackers, potentially flooding the market with autonomous exploits.
- Defensive AI will eventually improve software security, but in the short term attackers will hold a significant advantage, especially against resource‑constrained state and local entities.
- Leaders must treat cyber preparedness like terrorism preparedness: retire legacy software, adopt modern security tools, conduct regular threat briefings and tabletop exercises, and establish manual fallback communications.
The Evolving Threat Landscape
Nicole Perlroth emphasizes that the cyber threat environment is moving faster than ever. While ransomware once dominated headlines, the primary danger now comes from state‑sponsored actors—particularly China—who are quietly penetrating state and local computer systems and critical infrastructure such as water treatment plants, ports, railways, and their vendors. These intrusions are not about immediate data theft or ransom; they are strategic positioning for future escalation scenarios, enabling adversaries to disrupt essential services and sow panic when geopolitical tensions flare.
Why State and Local Governments Are Prime Targets
Perlroth notes that local governments are the most frequently targeted entities because a successful attack would be highly visible—imagine a mayor appearing on national TV explaining why the water supply has been cut off or contaminated. Large utilities like PG&E invest heavily in enterprise‑grade security, but many municipal water and power agencies rely on legacy software that cannot be patched, making them low‑hanging fruit for adversaries seeking to create chaos and political pressure with minimal effort.
Case Study: Littleton, Massachusetts
A concrete illustration comes from Littleton, Mass., where the city’s Electric Light and Water Departments learned in 2023—via an FBI and CISA alert—that they had been infiltrated by Volt Typhoon, a state‑sponsored Chinese hacking group. The attackers targeted a small utility serving only 15,000 residents precisely because it is easier to breach than a major corporation. Disrupting water and power in such a community can generate widespread confusion and pressure on policymakers, demonstrating the strategic value of hitting modest‑scale infrastructure.
Iran’s Opportunistic Cyber Campaign
While China’s operations are methodical and long‑term, Iran’s cyber activity is driven by an existential perception of the current conflict. Iranian actors launch aggressive campaigns against officials involved in cease‑fire negotiations and simultaneously target local infrastructure—water facilities, power grids—using simple exploits like default passwords and unpatched software. Their goal is not prolonged espionage but immediate disruption, exploiting any open door they can find.
AI’s Role in Automating Attacks
Ransomware persists, but artificial intelligence is changing how it operates. AI can now scan for open vulnerabilities, breach systems, encrypt data, and manage ransom negotiations without human intervention, automating the entire kill chain. Ransomware groups are even training AI chatbots to identify the most valuable assets to encrypt, gauge likelihood of payment, and negotiate for maximum psychological pressure. Consequently, organizations that neglect basic hygiene—such as timely software updates or multifactor authentication—are increasingly likely to be compromised automatically.
The Rise of AI‑Discovered Zero‑Days
Perhaps the most alarming development is AI’s ability to uncover previously unknown vulnerabilities. Anthropic’s preview of the Mythos model demonstrated that it can find severe, zero‑day flaws in widely used operating systems and browsers—bugs that had eluded human reviewers and automated scanners for up to two decades. In the security world, zero‑days are prized because they give attackers an invisible doorway; historically, selling them fetched millions. AI now lowers the barrier to entry, enabling rapid, large‑scale discovery and exploitation of these flaws by anyone who can access the model.
Defensive Potential of the Same Technology
Perlroth acknowledges that AI will also strengthen defenses. By using AI to vet code before release and to retroactively fix vulnerable software, organizations can achieve a significant uplift in security resilience. However, she cautions that the defensive benefits will likely lag behind the offensive surge, at least for the next few years. During this window, attackers will enjoy a pronounced advantage, especially against entities that lack the resources to keep pace with rapid AI‑driven threat evolution.
Practical Steps for State and Local Leaders
To counter these threats, Perlroth urges leaders to treat cyber readiness with the same seriousness as terrorism preparedness. Core actions include: retiring outdated software, adopting modern cybersecurity tools from top providers, and upgrading industrial control systems used by water and power authorities with purpose‑built security solutions. Although budget constraints make these upgrades challenging, she argues that maintaining legacy systems is no longer viable; it is a national‑security imperative to fund modernization.
Preparedness Through Planning and Training
Beyond technology, leaders must institutionalize cyber‑incident response planning. Regular threat briefings keep officials informed of emerging risks. Tabletop exercises—simulated attacks that walk through decision‑making, communication, and recovery—help teams identify gaps before a real event occurs. Crucially, agencies should establish manual fallback processes and alternate communication channels (e.g., radio, satellite phones) to maintain coordination when email and networks are down.
Conclusion: A Call to Action
The convergence of persistent state‑sponsored espionage, opportunistic attacks from nations like Iran, and AI‑powered automation creates a uniquely dangerous environment for state and local governments. While the long‑term promise of AI‑driven defense is real, the immediate future will likely see attackers exploiting vulnerabilities faster than defenders can patch them. By modernizing infrastructure, embracing best‑practice security, and treating cyber incidents as high‑stakes emergencies, leaders can reduce their exposure and protect the essential services their communities depend on.

