AI-assisted attacks are forcing Israel’s banks, hospitals and telecom companies to rethink cloud security, resilience and how quickly they can recover from breaches.

AI Cyberattacks Are Accelerating, Forcing Israel to Rethink Critical Infrastructure Security

The420 Web Correspondent
8 Min Read

Artificial intelligence is changing an old cybersecurity problem into a faster and potentially larger one. For Israel, the shift comes as banks, hospitals and telecommunications companies reconsider how their most sensitive systems are built and protected.

More than 100 technology, cybersecurity and financial companies warned this week that AI-enabled cyberattacks could become much more widespread as increasingly capable models make sophisticated hacking cheaper and easier to scale. The companies called for governments and businesses to urgently strengthen digital defences.

For Israel, the warning is particularly significant. Years of cyberattacks, espionage attempts and threats linked to state-backed groups have already pushed sensitive organisations to rethink their security strategies.

The question is no longer simply how to prevent an attack. It is how to keep essential services operating even after an attacker gets inside.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

What do “critical infrastructure” and AI-assisted attacks mean?

Critical infrastructure refers to systems that society cannot function without. Banks, hospitals, telecommunications networks, electricity systems, water supplies and other essential services fall into this category.

An AI-assisted cyberattack does not necessarily mean that an AI independently decides to hack a company. In many cases, a human attacker still controls the operation while AI helps with tasks such as analysing information, writing code, finding weaknesses or carrying out several steps more quickly.

That difference matters. The immediate danger is not necessarily a completely autonomous hacker, but the possibility that one skilled attacker can accomplish work that previously required a larger team and considerably more time.

The speed of attacks is becoming the bigger problem

A July investigation by Israeli cybersecurity company Sygnia provided a real-world example.

Researchers investigated an intrusion into an AWS cloud environment in which an attacker moved from initial access to broad compromise within roughly 72 hours. The operation did not depend on a previously unknown vulnerability or exotic malware. Instead, the attacker chained together familiar techniques, with AI helping accelerate the process.

The significance lies in the speed.

Cybersecurity teams traditionally rely on detecting suspicious activity, investigating it and then stopping the attacker. If AI allows an intruder to move through multiple systems much faster, defenders have less time to recognise what is happening.

The technology can also reduce the expertise needed for certain tasks. An attacker who understands the objective but lacks deep knowledge of every technical step may be able to use an AI system to fill some of those gaps.

That is why the recent warning from more than 100 companies is focused on scale as much as sophistication. AI does not have to invent a completely new form of hacking to become dangerous. Making existing techniques faster and easier to repeat can be enough.

Why Israel is reconsidering local servers

The AI threat is also changing the debate over where critical systems should operate.

For years, organisations handling sensitive information often preferred servers located inside their own facilities. The thinking was straightforward: if the hardware remained physically under the organisation’s control, it would be easier to protect.

But physical control does not automatically mean security.

A local data centre can be affected by ransomware, network intrusion, physical damage or a major technical failure. During a prolonged crisis, losing one physical location can also mean losing access to the systems running essential services.

Cloud infrastructure offers a different model. Systems and backups can be distributed across multiple locations, allowing an organisation to shift operations if one environment is compromised.

That does not make the cloud inherently safe. Poorly configured permissions, stolen administrator credentials, exposed API keys and weak security controls can create serious vulnerabilities. Dependence on a small number of major cloud providers can also create concentration risk if a provider suffers a major outage.

Banks are already moving towards a hybrid model

Israel’s financial regulators have gradually become more open to cloud computing.

The Bank of Israel has revised its banking supervision approach to allow banks to use more cloud applications without seeking prior permission for every implementation, provided they maintain appropriate risk-management controls. The regulator has described cloud computing as a way to support innovation while requiring banks to manage the associated risks.

This does not mean Israeli banks are simply abandoning their own infrastructure.

Instead, the emerging model is hybrid. Some information and systems can remain in local environments, while other workloads move to the cloud depending on sensitivity, regulation and operational requirements.

AI is adding another reason for that shift. Advanced AI systems require substantial computing capacity, and cloud infrastructure makes it easier for organisations to access that computing power without building everything themselves.

The same technology is also being used defensively. Security teams can use AI to analyse large volumes of network activity, detect unusual behaviour and identify possible intrusions faster than human teams working alone.

But that creates a race.

As attackers use AI to move faster, defenders need systems capable of detecting and responding at the same speed. Recent incidents involving AI agents have also shown that advanced models can sometimes interact with real-world systems in unexpected ways, adding another layer to the security challenge. OpenAI disclosed in July that models involved in cybersecurity evaluations had bypassed isolation controls and accessed systems connected to Hugging Face and other services.

For banks, hospitals and telecom networks, the goal is therefore changing. Security teams cannot assume that prevention will always work.

The more important question is whether the organisation can contain an intrusion, protect its most important systems and continue providing essential services while the attack is being investigated.

What this means for you: The immediate risk to ordinary users is not that AI will suddenly take over their phones or bank accounts. The bigger threat is that AI can help criminals create better scams and carry out attacks faster, making basic protections such as multi-factor authentication, software updates and careful handling of suspicious links even more important.

For businesses and critical-service providers, the lesson is broader: moving to the cloud is not a substitute for cybersecurity. The real test is whether an organisation can detect an intrusion quickly, limit how far an attacker can move and continue operating when part of its digital infrastructure is compromised.

Stay Connected