‘Bad actors on steroids’: Forescout CEO warns of crowdsourced hacktivism targeting critical infrastructure
A new report from Forescout Technologies warns that adversary governments are increasingly leveraging crowdsourced hacktivism as a tactic to breach critical infrastructure. It’s a new kind of cyber campaign that’s harder to trace and taking on increasingly ambitious targets.
“Nation-state bad actors were using multiple hacktivism groups … crowdsourced to solve problems,” said Forescout CEO Barry Mainz in a recent Cyber Focus interview. “It’s not 10 people sitting in a room somewhere; it could be up to several thousand.”
The report, produced by Forescout’s Vedere Labs (its internal threat research team), documents recent examples of programmable logic controllers (PLCs) and other embedded devices being analyzed en masse by nation-state-aligned groups. The goal, Mainz said, is to identify vulnerabilities in legacy operational technology (OT) systems, especially in sectors such as water and energy, that are often still running outdated protocols.
While that tactic is already playing out, Mainz says the next wave of threats is taking shape – fueled by emerging technologies such as quantum computing and agentic artificial intelligence. “We’ve got bad actors on steroids because that agentic AI can learn, and I’ve got a super-powerful engine behind it to go do bad things fast,” he said. “It’s like an elephant that can tap dance.”
These systems won’t just follow instructions – they can adapt, iterate and exploit weaknesses at machine speed. Pair that with the ability to break conventional encryption, and any system lacking quantum-safe cryptography becomes an easy target. “If your cyber vendor doesn’t have quantum-safe technology built in, it’s a problem,” Mainz said.
But even with better technology, Mainz said, defenders need better coordination. Too often, IT and OT teams operate in silos, each focused on their own systems and standards. “The culture is, ‘Hey, I’m in OT, stay out of my business. I’m in IT, stay out of my business,’” he said. “And I think this lack of ‘hey, let’s go and take an approach together’ is missing.” That disconnect, more than any one exploit, may be creating the most persistent vulnerabilities.
Mainz also warned that many organizations are still approaching cybersecurity reactively, only investing after a breach. “Every one of the times we’ve engaged with a large corporation and they had an issue, it was costing them way more than if they would have just bought the [necessary technology protections] up front,” he said.
The full conversation is available from Cyber Focus, the podcast produced by Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security.