AI Attacks US Water Plants, Apollo Beaten by a Phone Call, Kids’ Hospital Breached Again
Five federal agencies just warned that hackers are using AI to attack the computers running America’s water plants and factories. That same week, a trillion-dollar investment firm was breached, not by a virus, but by a phone call. The hard part of hacking is disappearing. Every business owner needs to understand why. What used to keep attackers out is now what lets them in. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week’s stories for executives, owners, and operators who don’t have time to keep up with cyber news but can’t afford to be blindsided. Start with the story that should stop you cold. The NSA, CISA, the FBI, the Department of Energy, and the EPA issued a rare joint warning: hackers are using AI to write code that attacks Siemens industrial controllers, the small computers that physically run water systems, power, and manufacturing. They took free, legitimate engineering tools and had AI turn them into custom attack software. The agencies say this dramatically cuts the skill and time an attack like this used to require. Difficulty was the wall that kept amateurs out of industrial systems. AI is tearing it down. And it is not theoretical. Security firm Dragos already documented a real intrusion where someone with no industrial background used commercial AI to go after a water utility’s controls. The advisory names six sectors in the line of fire, from energy and water to food and manufacturing. These attacks are as weak as they will ever be, because the AI only gets better from here. Then Randy takes on Apollo Global Management, the Wall Street giant with about a trillion dollars under management. Attackers didn’t break its technology. They called employees pretending to be internal IT, then guided them to fake login pages that captured their passwords and security codes. From there, they reached names, birth dates, home addresses, and Social Security numbers. This was not a lone hacker. Google ties it to a professionalized extortion crew that moves from one industry to the next running the same script, with demands that often start around three million dollars. A firm with a massive security budget was beaten by a convincing conversation, and a class-action lawsuit started forming within days. If a phone call works on Apollo, it can work on your team too. Reginald closes with SickKids, one of the most respected children’s hospitals in the world. No patient records were touched. Employee and job-applicant data leaked through a flaw in third-party software the hospital didn’t even build. Consider that last group: job applicants who handed over Social Security numbers to a place they did not even work yet. This repeat victim has now been burned by outside software three times, and it fits a bigger pattern: through the first half of 2026, vendors were involved in 43 percent of healthcare breaches. Another vendor breach this year hit 1.8 million people. Your biggest risk is often a company you’ll never meet, inside a tool you already trust. • How hackers are using AI to attack the industrial controllers behind US water and power • Why Apollo Global Management got breached by a phone call, not a virus • How SickKids leaked employee and applicant data through a vendor’s software • Why the skill it takes to attack a business is collapsing fast • What “verify who’s really calling” actually looks like for your team • How to find the vendors quietly holding your most sensitive data • The one thread connecting all three: what used to keep attackers out now lets them in Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #AI #CriticalInfrastructure #Apollo #DataBreach #SocialEngineering #VendorRisk #SickKids #BusinessRisk #MSP #SmallBusiness