Skip to content

Data Centers And AI Companies Face An Intensifying Threat Environment

Mark Freedman |    August 28, 2026

Image of data center

Data centers and artificial intelligence (AI) companies face a rapidly intensifying threat environment. Of 13,322 posts Liferaft collected across 13 platforms over a recent 175-day window, roughly one in three contained threat-themed language such as arson, sabotage, Molotov, or 'blow up.' That volume hit new peaks in late July and early August, 12% above the previous high set in May.

The security thinking inside the industry has not caught up. Most corporate security programs at AI companies and data center operators were built for a technology-company threat model: workplace violence, executive travel, insider risk, and site access control. What those programs now face looks closer to an infrastructure protection problem, with a physical attack surface spread across dozens of remote sites, a political dimension driven by local opposition, and, since March, a nation-state dimension. Those are different problems, and they demand different intelligence.

 

Different Threats Converging On The Same Target Set

Threats to data centers and AI companies are coming from three overlapping actor categories with distinct methods and objectives.

Lone Actors And Domestic Extremists

In early April 2026, an Indianapolis city councilman awoke to 13 shots fired into his front door, with a note reading 'no data centers' tucked under his doormat. The shooting came days after he publicly backed a data center rezoning in his district. Police described it as an isolated, targeted incident, and no motive has been formally established. Later that same week, a 20-year-old man threw a Molotov cocktail at Sam Altman's residence, then attempted to force entry into OpenAI headquarters, threatening to harm anyone inside. Prosecutors later said he had traveled from Texas intending to kill Altman and had written at length online about AI as an extinction risk.

Neither incident is without precedent. In 2021, a Texas man was sentenced to ten years in federal prison for plotting to bomb an Amazon Web Services (AWS) facility in Virginia. West Point's Combating Terrorism Center argued this year that the rise of AI is generating the structural preconditions for an increase in anti-technology political violence, with data centers, local officials, and AI executives among the near-term targets.

Activists

The nonviolent movement is expanding, and it is broader politically than many security teams assume. A national day of protest on July 18 produced 142 protests across 42 states, coordinated by HumansFirst, a group co-founded by a former Tea Party organizer. Reuters reported that a June Reuters/Ipsos poll found only 14% of Americans would support a data center being built in their community. Opposition to this buildout runs across the political spectrum, which makes it harder to model and more durable than a single-issue campaign.

The line between activism and sabotage is also blurring overseas. Extinction Rebellion activists in Amsterdam threw balloons filled with a chemical mixture at the concrete foundations of a data center under construction by Pure Data Centres, with Microsoft as the expected anchor tenant. The group said the mixture was designed to degrade the concrete and corrode the steel reinforcement. The developer reported no structural damage and no delay to construction. The tactic failed, which is arguably the more useful detail for planning purposes, because the intent to cause physical damage to a facility represents an escalation regardless of whether it worked.

Foreign Nation-States

Nation-state adversaries are now treating hyperscale commercial data centers as legitimate military targets. Iran's Islamic Revolutionary Guard Corps established the precedent on March 1, 2026. Drones directly struck two AWS facilities in the United Arab Emirates, and a third site in Bahrain sustained damage from a nearby explosion. The strikes impaired two of three availability zones in the UAE region and one in Bahrain, taking down banking, payments, and enterprise cloud services across the Gulf. Because multiple zones failed at once, standard redundancy models failed with them.

That precedent will not stay confined to the Middle East. The Cybersecurity and Infrastructure Security Agency (CISA) already tracks Chinese, Russian, and North Korean pre-positioning across U.S. critical infrastructure, and data centers should be assumed to sit inside that target set.

 

Data Centers Are Being Treated As National Security Infrastructure

Data centers support core functions across financial services, energy, healthcare, defense, and government. The March strikes made that dependency visible in a way that abstract arguments never did. When the availability zones went down, banks, payment processors, and enterprise software customers across an entire region went down with them.

Washington has noticed. A May 2026 congressional hearing examined whether AI data centers should be formally designated as critical infrastructure, in part because no federal framework currently answers which agency leads when a commercial data center is attacked. Some form of designation, or at least significantly heightened attention from CISA and other federal agencies, is likely inside the next 24 months.

The practical consequence tends to arrive before the designation does. Regulatory attention brings reporting obligations, minimum security standards, and pointed questions from boards and insurers about what the security program actually covers. Answering those questions credibly requires a documented picture of the threat environment around each site, and that picture takes months to build.

 

What Security And Intelligence Teams Should Do Now

Four priorities stand out for teams working in the AI and data center industry.

 

1. Distinguish Between Actor Classes

Extremists, activists, and nation-states have different objectives, tactics, and indicators. Protective measures that treat them uniformly end up over-invested against one and under-invested against another. The lines do blur. The Altman attacker was radicalized by AI risk narratives circulating in online communities, and foreign adversaries have an obvious interest in amplifying domestic opposition. Distinction remains the right starting point, with the overlaps tracked deliberately rather than assumed away.

 

2. Anchor Your Collection To Facilities, Executives, And Local Officials

Social media has become a primary source for understanding public sentiment about AI and data centers and for identifying threats against these assets early. Queries should be built around specific site names and addresses, project names still working through permitting, executive names and known aliases, and the local officials who vote on your projects. The Indianapolis case is instructive here, because the person attacked held elected office rather than a job at the company. Continuous threat monitoring and alerting against those terms gives teams a chance to see grievance forming before it moves offline, and the same approach extends to executive protection for principals who are now being named directly in that conversation.

 

3. Track Trend Lines Alongside Individual Posts

A single violent post is a triage question. A sustained rise in threat-themed language around a named facility is a planning question, and the two require different responses. The increase in threat chatter between May and August is exactly the kind of signal that matters at program level, where risk trends and analysis over time turns a stream of alerts into something a CSO can brief to a board. Establishing a baseline now gives the next spike something to be measured against.

 

4. Coordinate Across Sectors,  Particularly Energy And Water

Data centers are physically entangled with electricity and water infrastructure, and in some cases the same actors are moving against those adjacent industries in parallel. Local opposition often forms around utility rates and water draw long before it forms around the facility itself, which means the earliest indicators frequently surface in a county commission meeting rather than a threat feed. Cross-sector intelligence sharing helps close that visibility gap.

 

Where This Leaves Operators

Threats to this industry are maturing faster than the security programs built to meet them. The actors are distinct, the tactics are escalating, and the regulatory picture is moving. Progress starts with an honest assessment of what the current program was designed to handle and where that design stops, followed by the collection work required to tell the difference between a loud protest, a serious grievance, and something considerably worse.

Mark Freedman

Mark Freedman

Principal & CEO, Rebel Global Security

Mark Freedman is Principal and CEO of Rebel Global Security and was formerly the Chief of Staff for the U.S. Department of State’s Counterterrorism Bureau. This post is part of Liferaft and Rebel’s collaborative work to analyze the evolving global threat environment and provide critical insights to private sector and government clients.