Back to The Curiosity Edit
Cyber & Tech·Issue 011

When the Hack Hits Home

The cyber threats behind your morning coffee, commute, and prescription refill

By Jade Rhedrick  |  Jadeofalltrades

⏱ 9-minute readCritical Infrastructure • Cybersecurity • Everyday LifeRabbit rating

Your faucet, your toll account, and your prescription refill have something in common: digital dependencies. Recent incidents reveal how attackers exploit those connections, while AI helps them do more of the work at greater speed. Here is what that means for an ordinary day, and where a little preparation helps.

Reporting updated October 2, 2026. Earlier incidents are identified as historical context.

Share this essay
The Curiosity Edit Issue 011 cover: Jade seen from behind making morning coffee as a glowing cyber-dashboard overlays the kitchen window, When the Hack Hits Home
Issue 011, Cyber & Tech

Before Coffee, You’ve Already Logged On

Shower. Coffee. Phone check. Kids out the door.

You may not have opened your laptop yet, but your morning is already depending on digital systems.

We usually picture a cyberattack as a suspicious email, a stolen password, or another “your information may have been affected” notice. Sometimes, though, the first sign is a water advisory or a prescription that cannot be processed.

And suddenly, cybersecurity has entered the group chat with your actual life.

“Behind everyday convenience is a network of systems we rarely notice until something stops working.”

Making coffee is not the security flaw. The vulnerabilities sit in the equipment, accounts, and shared services supporting that routine. The consequences reach the kitchen anyway.

Your Faucet Has a Digital Dependency

Water utilities use operational technology, or OT, to monitor and control physical equipment, including pumps and valves.

A July 30, 2026 FBI/EPA advisory reported cyber incidents at water and wastewater utilities in at least seven states. Attackers changed settings on internet-connected industrial controllers, disrupting monitoring and control. Reported effects included pressure loss and flooding.[1]

An attack does not automatically mean contaminated drinking water. Losing sight of a process, losing control of equipment, and confirmed contamination are different outcomes. However, the FBI noted that pressure loss could allow untreated groundwater to enter pipes.[1]

The advisory also identified a less obvious exposure: third-party vendors using similar network configurations across customers. A repeated weakness can put multiple utilities within reach of the same approach.[1]

At home: a disruption could change how you cook, bathe, clean, or prepare a child’s drink. A childcare center or restaurant could face difficult decisions about staying open.

A technical incident can become a household logistics problem remarkably quickly.

The Lights Are Only Part of the Story

Cyberattacks can interrupt electricity. CISA documented attacks against Ukrainian power companies that caused outages in December 2015.[2] That example demonstrates the possibility; it does not establish a current outage in a U.S. community.

The immediate dependencies are familiar: refrigeration, heating, cooling, phone charging, and powered medical equipment.

The less obvious ones connect entire services. CISA identifies energy, communications, water, and transportation as supporting almost all other infrastructure sectors.[3] Depending on backup capacity and duration, a disruption in one can strain others.

At home: the concern may be spoiled groceries, a missed workday, or keeping essential equipment running.

The consequences vary. For someone who cannot easily relocate or depends on powered medical equipment, even a short interruption can require careful planning.

The Hack Doesn’t Have to Reach the Machinery

One of the most overlooked details is that the system attacked and the service interrupted can be different.

In May 2021, Colonial Pipeline proactively halted pipeline operations to contain ransomware affecting its information technology systems.[4]

Business technology was compromised. A physical service was paused.

Organizations may shut down operations while they investigate, contain an incident, or confirm that it is safe to continue. That protective decision can still create disruption for customers.

At home: a fuel interruption could complicate the commute, school pickup, or a planned trip.

Attackers do not have to take direct control of every piece of equipment to affect the people who depend on it.

Your Pharmacy Has a Behind-the-Scenes Dependency, Too

After the February 2024 Change Healthcare cyberattack, CMS reported effects across pharmacies, hospitals, and physician offices, including impacts on some people’s ability to obtain care or prescriptions.[5]

You did not need your own Change Healthcare account to feel the consequences.

Many organizations depend on shared vendors for transactions, insurance checks, and payments. One company’s disruption can reach people across many others.

Imagine arriving for a refill: the medication is on the shelf, but the system needed to process it is unavailable.

At home: “the system is down” can become extra calls, another trip, or uncertainty about accessing care.

That is why a vendor you have never heard of can still matter to your Tuesday.

The dependency extends beyond insurance transactions. Following a March 11, 2026 cyberattack, medical technology supplier Stryker reported disruptions to order processing, manufacturing, and shipping. It used manual ordering where available while restoring systems. The company said its products, including connected devices, were unaffected and safe to use.[10]

The everyday connection: patient care depends on supplies arriving as well as equipment working. A supplier’s business systems can become a pressure point without a bedside device being compromised.

The Road Can Stay Open While the Revenue Stops Flowing

Drive through a toll plaza. Keep going. Behind the scenes, the system that collects your payment has become a ransomware target.

That happened in Puerto Rico on April 16, 2022, when ransomware affected the central systems of AutoExpreso, its electronic toll service. A January 2025 Inspector General report revisited the incident as part of an examination of toll-system contractors and controls.[8]

Drivers could still travel, but account services were disrupted. Officials reported that users could not reload accounts, pay fines, or view balances. They suspended fines during the disruption.[9]

The financial distinction matters: tolls continued to be recorded for later collection.[15] The attack disrupted the payment process; it did not permanently make every crossing free. By July 1, 2022, officials said 70% of users had caught up with their accounts, representing $24 million collected. The system had resumed operations on May 23.[14]

That figure reflects money collected during recovery, not a verified total loss. It shows the scale of the payment backlog and why delayed revenue collection matters to a public agency.

The everyday connection: the pavement can remain usable while the service behind it struggles. Drivers face account uncertainty and accumulated charges. The agency faces interrupted collections and the work of restoring systems and reconciling transactions.

For toll roads and bridges, the digital dependency extends beyond the physical structure. A compromised payment platform can disrupt the financial operations supporting transportation, even while traffic keeps moving.

When Convenience Becomes a Safety Dependency

Automatic payments. Remote monitoring. Electronic prescriptions. Digitizing everyday services saves time and improves access. It also makes reliable software, accurate data, and secure connections part of how essential services operate.

The stakes can extend to physical safety:

  • Water: compromised controls can disrupt pressure and monitoring. Pressure loss can create a pathway for untreated groundwater to enter pipes.[1]
  • Power and industrial equipment: malicious changes to controllers can potentially cause safety incidents, equipment damage, and disrupted processes, as the August 2026 federal advisory warns.[11]
  • Healthcare: HHS identifies delayed procedures, patient diversion, and strained care capacity among the consequences of hospital cyberattacks. For someone needing timely treatment, an unavailable system can become a patient-safety issue.[16]

These are documented risks across sectors, not confirmed outcomes of every incident described here. AutoExpreso illustrates financial and administrative disruption; it does not establish damage to bridge structures or a traffic-safety incident.

The question behind digitized “everything”: if the connection fails, is there a safe way to keep the essential service running?

Security, tested fallback procedures, and accurate information belong in the design of convenience. They determine how much protection people retain when the technology stops cooperating.

AI Gives the Same Weakness More Reach

Attackers already used scripts, phishing kits, and bulk messaging before generative AI. What is changing is how much analysis, coding, and convincing communication can be delegated, with less hands-on work at each step.

The infrastructure connection is documented. On August 19, 2026, the NSA and partner agencies warned that actors were conducting reconnaissance and developing capabilities against U.S. Siemens industrial controllers using AI-generated exploitation scripts. The targeted sectors included energy, water, manufacturing, chemicals, and agriculture.[11]

That warning describes active targeting and capability development. It does not establish that AI caused the July water incidents or the healthcare and transportation examples above.

One campaign shows the scale of delegation. In November 2025, Anthropic reported on an espionage operation it detected that September. According to the company:[12]

  • Roughly 30 organizations were targeted, with successful infiltration in a small number of cases.
  • 80–90% of campaign work was performed by AI, with humans intervening at approximately four to six critical decision points per hacking campaign.
  • At peak activity, the AI made thousands of requests, often multiple per second.

These are the provider’s estimates for one observed operation, not an industry-wide success rate. The AI also invented credentials and sometimes mistook public information for stolen secrets.[12]

The practical shift is delegation: reconnaissance, code development, and data sorting can move through a workflow with fewer human handoffs. That can stretch an attacker’s capacity across more targets. The evidence supports increased speed and reduced manual effort; it does not make every attack autonomous or successful.

The everyday deception scales, too. The FBI warns that criminals use generative AI to produce believable messages faster, translate them, reduce spelling errors, and generate fraudulent website content.[13] Better grammar is becoming a weaker reassurance.

For an unexpected utility notice or healthcare message, the useful question is: Can I verify this request through a channel I already trust? These findings document AI misuse in other operations; they do not establish AI involvement in the AutoExpreso attack.

A Little Preparation, Less Scrambling

Start with what is useful and manageable:

  • Water: CDC recommends at least one gallon per person per day for three days. Follow the specific local advisory. Boiling kills germs, but cannot make water containing toxic chemicals safe.[6][7]
  • Power: keep flashlights and charged power banks accessible. If you depend on powered medical equipment, develop a backup plan with your care team.
  • Essential information: keep emergency contacts, a medication list, and your pharmacy number available offline.
  • Reliable updates: verify disruption notices through established utility, healthcare, and local government channels.
  • Transportation: during a toll-system outage, keep account and payment records. Follow the agency’s official guidance on accumulated charges, grace periods, and service restoration.

These basics also help during storms and equipment failures. You can build them gradually.

✦ Limitless Reflection

“If an essential service stopped working tomorrow, which part of your day would become difficult first?”
, Jade Rhedrick  |  Jadeofalltrades

© Jadeofalltrades. Unauthorized reproduction prohibited.

Start there. Choose one small step that would make that disruption easier to manage.

The security of a faucet, a fuel supply, or a pharmacy transaction may sound distant until it intersects with dinner, school pickup, or someone’s health.

That connection deserves a place in our cybersecurity conversations.

Let’s go down the rabbit hole 🐇

Which everyday service has a digital dependency you had never considered? What would you want to understand about it before it stopped working?

Continue Exploring

Revisit Issue 010: The Golden Opportunity Inside the LinkedIn DM I Almost Didn’t Trust A closer look at verification, preparation, and the opportunities worth investigating.

Explore more: The Curiosity Edit

Sources & Further Reading

  1. FBI/EPA: Water and wastewater controller attacks, July 30, 2026
  2. CISA: Cyber-Attack Against Ukrainian Critical Infrastructure
  3. CISA: Critical Infrastructure Systems
  4. DOE: CESER 2021 Emergency Response Recap
  5. CMS: Change Healthcare cyberattack memorandum, March 6, 2024
  6. CDC: How to Create an Emergency Water Supply
  7. CDC: How to Make Water Safe in an Emergency
  8. Puerto Rico Inspector General: AutoExpreso contractor and toll-system examination, January 8, 2025
  9. Puerto Rico DTOP: AutoExpreso incident and toll-recording updates, April 2022
  10. Stryker: Customer updates on the March 2026 network disruption
  11. NSA: AI-generated scripts targeting industrial controllers, August 19, 2026
  12. Anthropic: Disrupting an AI-orchestrated cyber espionage campaign, November 13, 2025
  13. FBI IC3: Generative AI and financial fraud, December 3, 2024
  14. Puerto Rico DTOP: AutoExpreso recovery collections and grace period, July 1, 2022
  15. Puerto Rico DTOP: Tolls continued to be recorded; fines suspended, April 19, 2022
  16. HHS: Cyberattacks, healthcare infrastructure, and patient safety
Share this essay