Summary
This article provides a structured assessment of the potential malign use of Geographic Information Systems (GIS) by threat actors of varying technical sophistication to target U.S. cities and critical infrastructure. Using a newly constructed critical infrastructure facility in the United States as the operational test case, the use cases explore how open-source geospatial tools can be used to identify, model, and potentially exploit critical infrastructure vulnerabilities. The facility was selected for its emergent relevance to regional and national supply chains, logistical novelty, and its appearance in both regional and national public discourse surrounding immigration and rural industrial development.
The assessment includes four discrete use case examples corresponding to escalating levels of threat actor capability: Tier 1 (one without and one with AI augmentation), Tier 2, and Tier 3 (see Figure 1). Each scenario demonstrates how openly accessible data and commercially available GIS and AI tools can be operationalized to perform tasks such as infrastructure targeting, route planning, emergency response delay modeling, reconnaissance staging, among others. This framework assists in evaluating adversarial capabilities, mapping threat vectors, and anticipating how generative AI may further reduce the technical barriers to high consequence targeting.
Threat actors across varying skill levels can effectively identify and exploit vulnerabilities in critical infrastructure using open-source geospatial data. Even Tier 1 actors, when augmented by generative AI like ChatGPT, Claude, or Google Gemini, can analyze site access, infer vulnerabilities, and devise attack strategies including physical sabotage, low-level cyber tactics, and disinformation campaigns. More sophisticated actors leverage advanced GIS platforms to model supply chains, critical dependencies, and emergency response scenarios, with the ability to closely mimic professional geospatial intelligence processes. Crucially, generative AI can compress traditional skill barriersBrynjolfsson, E., Li, D., & Raymond, L. (2025). Generative AI at Work. The Quarterly Journal of Economics,140(2) 889–942, https://doi.org/10.1093/qje/qjae044[1] and enable non-experts to rapidly convert reconnaissance into actionable attack plans, significantly increasing the risk profile and challenging the reliability of existing infrastructure security paradigms.
Publication of this article does not constitute an endorsement of the contents, conclusions, or opinions of the author(s). The published article’s contents, conclusions, and opinions are solely that of the author(s) and are in no way attributable or an endorsement by the National Geospatial-Intelligence Agency, the Department of Defense, the United States Intelligence Community, or the United States Government. For additional information, please see the Tearline Comprehensive Disclaimer at https://www.tearline.mil/disclaimers.




