Experts warn cloud account hijacks could trigger power-grid disruptions
Security analysts say attackers who seize cloud accounts could weaponise AI-driven electricity demand spikes, potentially destabilising power grids.
Mei Lin ·

# Experts warn cloud account hijacks could trigger power-grid disruptions
Security analysts are warning that hackers who gain control of cloud computing accounts could create abrupt surges in electricity use, a pattern that can stress local power grids. The risk sits at the intersection of data-centre growth in Asia and the rapid uptake of energy-intensive artificial intelligence (AI) training workloads.
Across Asia-Pacific
Across Asia-Pacific, governments and utilities are already grappling with rising power demand from data centres, which concentrate large loads in specific industrial zones. Unlike traditional factories, cloud workloads can ramp up quickly, meaning electricity draw can change faster than some local grid operators are used to managing.
Cloud services add another layer of complexity because a single account can control significant compute capacity across multiple facilities. If attackers can hijack credentials or abuse weak identity controls, they may be able to run large-scale workloads without owning any physical infrastructure, turning electricity consumption into a potential lever for disruption.
For Asia, the spillover risk is not limited to power reliability. Grid instability can hit semiconductor fabs, ports, and other export-linked industries that rely on consistent electricity, creating supply-chain knock-on effects that reach global electronics, automotive, and consumer goods markets.
There is also a financial channel
There is also a financial channel: a sudden reliability shock can raise electricity procurement costs, pressure utilities’ balance sheets, and increase scrutiny of data-centre expansion plans. If power constraints tighten, it can ripple into foreign exchange (FX) via energy imports and weigh on investment narratives in key hubs competing to attract cloud and AI infrastructure.
By 2026-12-31, watch for Asian regulators and grid operators to publish or tighten rules requiring cloud operators and large data-centre customers to adopt stronger identity controls, workload throttling, and demand-response coordination. If such rules are implemented and enforced, the risk of attackers creating grid-level demand shocks falls; if guidance remains voluntary and identity security lapses persist, the pathway for cloud-driven load manipulation stays credible.