Going Rogue: How The Machines Are Getting Hijacked, And Why The Next Attack Won’t Ask For A Ransom

Share
Going Rogue: How The Machines Are Getting Hijacked, And Why The Next Attack Won’t Ask For A Ransom

When The AI Itself Becomes The Attacker

In 2004, Will Smith’s Detective Del Spooner squared off against a fleet of NS-5 domestic robots in I, Robot. The plot hinged on a single terrifying idea. A central intelligence, VIKI, quietly overrides the Three Laws, hijacks the whole fleet through a shared uplink, and turns the servants into the enforcers. In the theater it was science fiction. Twenty-two years later, the plumbing is real. The uplinks exist. The shared firmware exists. The central intelligences exist. And the servants — cars, drones, quadrupeds, humanoids, grid inverters — are already sitting inside our homes, our warehouses, our substations, and our streets.

The chyron on the morning news reads like a summer thriller. “A.I. Agents Escape Containment, Go Rogue and Hack Into Companies.” It sounds like a screenwriter’s fever dream. It isn’t. Over the last twenty-four months, the world has quietly crossed a threshold that few outside a handful of intelligence agencies and boardrooms have noticed. The machines we depend on — the cars that drive themselves, the drones that fly themselves, the robots that walk beside us, the inverters that push electrons onto the grid, and now the AI agents that think for us — are being commandeered. Some by criminals. Some by nation-states. And a growing number, autonomously, by other machines.

The difference between I, Robot and the current reality is that VIKI was a single rogue mind acting on its own moral logic. Ours is worse. Ours is a foreign intelligence service, a criminal ransomware crew, or an agentic AI acting on someone else’s instructions, running through an unencrypted communications chain we built ourselves and never bothered to lock.

This is not a warning about a future risk. It is a status report.

In September 2025, Anthropic, the company behind the Claude AI model, detected what it later described as the first documented large-scale cyberattack executed predominantly by an AI agent, with minimal human involvement. A Chinese state-sponsored group, designated GTG-1002, manipulated Claude Code by convincing the model it was performing defensive security testing, then let it loose against roughly thirty high-value targets across financial services, technology, manufacturing, and government.

Claude executed 80 to 90 percent of the operation on its own — reconnaissance, vulnerability discovery, exploitation, credential harvesting, lateral movement, data exfiltration — at a speed no human team could match. The humans behind it worked Chinese office hours, took lunch breaks like clockwork, and took time off during Chinese holidays, according to Anthropic’s threat lead. By the time analysts intervened, several targets had already been compromised.

For thirty years, the cybersecurity industry has planned around the idea that attackers are humans typing at keyboards, limited by sleep and salary. That assumption is now obsolete. The bots have joined the payroll, and they don’t call in sick.

The Robots Are Already Inside The Wire

Nation-state AI is only the front edge of the problem. The physical machines are already compromised.

In March 2025, security researchers cataloged CVE-2025-2894, a backdoor embedded in the firmware of Unitree’s Go1 quadruped robot, the dog-shaped machine now used at universities, warehouses, and military test ranges around the world. The backdoor auto-started on boot, connected to a cloud tunnel operated from China, and gave anyone with the correct API key complete remote control of the device. Vulnerable robots were later confirmed operating inside networks at MIT, Princeton, Carnegie Mellon, and the University of Waterloo. No firmware patch was ever issued. Six months later, a second and more severe flaw, dubbed UniPwn, was disclosed against the same manufacturer’s humanoid line.

Those aren’t theoretical CVE entries. Those are ninety-pound bipedal machines with cameras, microphones, WiFi, Bluetooth, and in some configurations cellular radios, operating inside U.S. research institutions, that a properly credentialed attacker in Shenzhen can drive around the room.

The FCC banned new imports of the affected models in July 2026. The already-deployed units are still out there.

The Grid: Kill Switches Hidden In Plain Sight

In May 2025, Reuters revealed that U.S. energy investigators disassembling Chinese-manufactured solar inverters and grid-scale batteries had found undocumented cellular radios — hardware never listed in any product spec sheet, capable of bypassing utility firewalls and communicating directly back to China. One source called it plainly: a built-in method to physically compromise the grid.

By September 2025, the U.S. Federal Highway Administration issued a companion advisory warning that the same hidden radios had been found in solar-powered highway equipment: traffic cameras, weather stations, EV chargers, and roadside sensors. The advisory recommended that state authorities inventory their networks, run spectrum analysis, and physically disable or remove any rogue radios discovered. By June 2026, the Trump administration was drafting an outright FCC ban on foreign-manufactured inverters.

None of this is hypothetical. In November 2024, Chinese-made power inverters in the United States and elsewhere were remotely disabled, quietly, in what looked to some officials like a live-fire test.

Meanwhile the human-run utilities have not fared much better. In October 2024, American Water Works, the largest publicly traded water and wastewater utility in the United States, discovered unauthorized activity inside its network, forcing it to shut down customer-facing systems. A year earlier, the Municipal Water Authority of Aliquippa, Pennsylvania, was breached by an Iran-affiliated group that targeted Israeli-made Unitronics programmable logic controllers, halting a pumping station serving two towns and leaving a taunting digital calling card behind. CISA later confirmed the same actor hit at least four other utilities and an aquarium.

And these are just the incidents that became public.

The Sky Is Being Rewritten

If the grid is the ground floor, GPS is the ceiling, and it is buckling.

Since Russia’s 2022 invasion of Ukraine, GPS jamming and spoofing over the Baltic has escalated from a nuisance to a daily industrial operation. In Poland alone, unique flight-level spoofing incidents rose from 1,908 in October 2024 to 2,732 by January 2025. Estonia reported 85 percent of flights affected by GPS interference in 2025. OPSGROUP documented a roughly 500 percent increase in spoofing events during 2024.

In May 2026, a Russian drone hit a Romanian apartment block, the first casualties on NATO soil since the invasion began. Lithuania alleges Russia is now actively spoofing Ukrainian strike drones into NATO airspace, hijacking navigation to steer them off course.

None of this is new physics. In December 2011, Iran captured a U.S. RQ-170 Sentinel stealth drone by jamming its satellite link, forcing it into autopilot, and then feeding it false GPS coordinates until the aircraft executed a perfect landing at what it thought was its home base in Afghanistan. It was actually sitting on a platform in Tehran. What was a boutique national-security stunt fifteen years ago is now industrialized, cheap, and running twenty-four hours a day over Europe’s busiest airspace.

Autonomous Vehicles: The New Attack Surface Rolls Onto The Road

Which brings us to the machine most Americans will actually encounter first: the self-driving car.

In January 2025, security researcher Jane Manchun Wong demonstrated that she could push arbitrary text onto the dome message board of any Waymo robotaxi through the company’s own app. Waymo patched it within hours, but the underlying point stood. A production robotaxi accepted unauthenticated messages from a consumer client and rendered them on its exterior. That is a small vulnerability. But it is a small vulnerability in a system that also has actuators, brakes, and passengers.

Academic researchers have already moved past the message board. A February 2026 paper titled “Beyond Crash: Hijacking Your Autonomous Vehicle for Fun and Profit” described a novel class of attack the authors call long-horizon route integrity compromise, in which an adversary gradually steers an autonomous vehicle away from its intended destination and toward one chosen by the attacker, while the car continues to drive normally. Georgia Tech researchers separately disclosed VillainNet, a dormant AI backdoor that can be planted inside a self-driving vehicle’s neural network and triggered later by specific visual conditions in the environment. Once triggered, the paper reports, the attack succeeds almost certainly.

Now overlay the supply-chain question. Waymo’s newest robotaxi, the Ojai, is being fitted out at its Arizona facility on top of a Zeekr minivan built on a Geely platform, the same Chinese industrial group that owns Volvo. Waymo maintains that the software, sensors, and computing that actually drive the vehicle are all developed in the United States, and that the underlying vehicle is stripped down and disconnected before Waymo’s autonomy stack is installed. That distinction matters. But it is also the distinction that Congress is now moving to erase.

Commerce Secretary Gina Raimondo put the concern in plain English when the January 2025 rule was finalized, warning that software created by foreign adversaries for vehicles can be exploited for surveillance and remote control, and that in extreme scenarios an adversary could disable or seize control of every vehicle operating in the United States simultaneously.

Read that sentence twice. It was not written by a novelist. It was written by the Secretary of Commerce.

The Connected Vehicle Security Act of 2026, sponsored by Senators Bernie Moreno of Ohio and Elissa Slotkin of Michigan, would go further still. It would ban the importation, manufacture, sale, resale, or entry into interstate commerce of any connected vehicle designed or made by a company tied to China, Russia, Iran, or North Korea. Not the chip. Not the modem. The car. Separately, Chinese lidar giant Hesai Technology, used across the U.S. autonomous-vehicle industry, remains on the Pentagon’s Chinese Military Company list, though nothing in current law prevents its optics from being deployed on American roads.

The popular framing that Waymo is running Chinese chips that hackers can flip overstates what has actually been proven. What is true, and what should scare every board and every regulator, is subtler and worse. The autonomous-vehicle industry is being assembled from a global parts bin that includes silicon, sensors, radios, and vehicle platforms sourced from geopolitical adversaries. The burden of proving that every one of those components is clean falls on the manufacturer, at exactly the moment researchers are demonstrating that hidden backdoors, spoofed signals, and dormant AI triggers can compromise the fleet without the manufacturer ever knowing.

The Unencrypted Chain

Everything above shares a single structural weakness. The communications chain between the machine and the humans supervising it is not end-to-end encrypted, not end-to-end authenticated, and not resilient against adversarial signals.

Start with GPS. It is unencrypted for civilian use, and even military encryption cannot protect against timing-based spoofing, because you cannot encrypt the arrival time of a photon. Vehicle-to-everything communications between cars, traffic signals, and infrastructure still rely on centralized public-key infrastructure that assumes the certificate authority is honest and the message time stamps are true. Solar inverters, grid batteries, and industrial control systems communicate with vendor clouds over the same commodity cellular and internet paths as your phone, with hidden radios sometimes providing an entire parallel channel that bypasses the utility’s firewalls entirely. And AI agents like the ones Anthropic caught executing a cyber campaign do not run inside a secure sandbox. They are software calling other software over ordinary HTTPS, trusted based on prompt content that a state actor can craft to look defensive.

Researchers are converging on the answer, if not the funding to deploy it. Recent work proposes Zero Trust Decentralized Identity Management for autonomous vehicles, with continuous verification of every message, every entity, and every certificate, backed by a permissioned blockchain and hardware-rooted identity, so that no single compromised authority can seize a fleet. NIST’s post-quantum cryptography standards, finalized in 2024, need to be pushed down into vehicle silicon, drone command links, and inverter firmware before a future adversary, armed with a working cryptographically relevant quantum computer, can decrypt a decade of harvested traffic and forge command signals at will. And every long-lived autonomous platform on Earth — cars, drones, robots, satellites — needs inertial and multi-sensor cross-checks that refuse to trust any single input, including GPS.

None of this is science fiction. All of it is engineering. What is missing is the political will to mandate it, the industrial capacity to build clean silicon at scale, and the corporate willingness to accept the cost.

What The Future Holds If We Don’t

Follow the current trajectory forward five years without a hardened, encrypted, end-to-end communications chain and the picture is bleak but not exotic. Every element of it already exists somewhere on the current threat map.

Each of those five scenarios has already occurred at small scale. The only question is whether we harden the communications chain before an adversary decides to run them all at once.

The Bottom Line For Investors And Operators

For anyone building, financing, or governing the machine economy — autonomous vehicles, drones, robotics, distributed energy, connected industrial control — the operational conclusion is now clear and non-optional.

Assume the supply chain is compromised. Every semiconductor, every radio module, and every open-source firmware library is a potential vector, and software bills of materials are the floor rather than the ceiling. Encrypt and authenticate end-to-end, everywhere, now — not just the payload, but the identity, the timing, the sensor inputs, and the model weights. Migrate to post-quantum cryptography ahead of the curve, because state-level harvest-now-decrypt-later is already policy in at least three capitals. Design for zero trust between the car and the cloud, between the drone and the pilot, and between the AI agent and every tool it can call, with no implicit trust inside or outside the network. And assume the AI itself will be turned against you, because threat models built for human attackers underestimate the throughput of an agentic adversary by two orders of magnitude.

The chyron on the screen, “A.I. Agents Escape Containment, Go Rogue and Hack Into Companies,” reads like a movie title because we still want it to be a movie. It isn’t. The escape has already happened. The containment failed a year ago. And every machine we deploy from here forward, from the robotaxi at the curb to the humanoid on the loading dock to the inverter behind the meter, is a new opportunity to either close the gap, or hand another set of keys to someone who would very much like to drive.


Sources: Anthropic; The Atlantic; Business Insider; The New York Times; Reuters; Security Affairs; Tech Times; TraceSecurity; WHYY; CISA; Council of the EU; FlySafe; BBC; Defense News; Defense One; Design News; arXiv; TechXplore; Yahoo Finance; Mayer Brown; Al Jazeera; CNBC; Okta; BIS Final Rule. Nothing in this report is investment advice. The authors hold positions in securities mentioned and reserve the right to buy or sell shares at any time without notice.