Cybersecurity officials are warning that a recent U.S. military operation in Venezuela has raised the risk of cyberattacks on critical American infrastructure like power grids, water systems, and communications networks. The Cybersecurity and Infrastructure Security Agency (CISA) reports that the U.S. already faces ongoing cyber threats from countries like China and Russia. These threats have grown more serious after the U.S. conducted a raid in Caracas targeting Venezuelan President Nicolás Maduro.While the U.S. hasn’t shared details about how the operation was carried out, experts believe it may have combined cyber tools with traditional military tactics to knock out parts of Venezuela’s power grid during the overnight mission. This approach is similar to past U.S. operations that used cyber capabilities alongside physical force.

Security experts are now advising critical infrastructure operators to prepare for a wave of potential cyberattacks. This pattern has happened before—after U.S. strikes on Iranian nuclear sites last summer, Western infrastructure saw increased hacking attempts in the weeks that followed. While Venezuela doesn’t have strong cyber capabilities on its own, its close ties with China and Russia could lead to attacks on already vulnerable U.S. energy, water, and communication systems.

Federal officials are urging organizations to strengthen their defenses immediately.

However, past experience suggests that major disruptions aren’t guaranteed. After the Iran operation, feared widespread outages across U.S. power, water, and transportation systems never happened. Still, there was a noticeable increase in hacktivist activity targeting those sectors.

Former Pentagon cybersecurity officials believe the U.S. may be entering a period where cyber retaliation becomes more common and potentially more damaging. China- and Russia-linked hackers may take advantage of these political tensions to put more pressure on U.S. infrastructure. Past situations have shown that smaller organizations with limited security resources—like local water utilities—are often the easiest targets.

After the Iran strikes, federal agencies warned that cyber retaliation often starts with low-cost, attention-grabbing tactics like denial-of-service attacks, ransomware, and widespread scanning of internet systems. CISA says it has been working to defend against these types of threats even before the Venezuela operation.

It’s still unclear exactly how the U.S. disrupted Venezuela’s power grid during the raid, and whether reliable cyber-based attacks on power grids are even possible without causing long-lasting outages. Industry experts say that while such operations can work in theory, they’re very complicated and hard to pull off precisely.

From a military perspective, analysts note that non-cyber methods—like special bombs that release carbon fibers—have historically been more reliable for disabling electrical systems. These “blackout bombs,” which the U.S. has used in several conflicts over the past thirty years, scatter treated carbon material that short-circuits transformers and power lines.

By comparison, cyber-caused power outages have only happened in a few cases and usually require extensive preparation. The well-known Russian cyberattacks on Ukraine’s power grid in 2015 and 2016 took months of planning and system infiltration to achieve outages that only lasted one to three hours. Experts emphasize that these operations require long-term planning and deep access to systems, which makes them more likely to be discovered before they can be executed.