Data centers, once obscure on the urban skyline, are now at the forefront in society as they have multiplied in recent years, increased electricity costs and depleted water supplies. Such grievances combined with their integral role in data storage, transfer, and redundancy have made the sites an attractive target for terrorists and other bad actors looking to harm the United States.
Read the paper: “Evaluating the Physical, Digital, and Sovereign Risks to U.S. Data Centers” explores methods of attacks and vulnerabilities, and makes recommendations for homeland security stakeholders. The paper’s authors are NCITE consortium experts Kevin Chen and Katrina McDermott, both master’s of public policy candidates in the Yale Schmidt Program on AI, Emerging Technology, and National Power.
Why it matters: Attacks on data centers put crucial American information at risk — in finance, energy, defense, and more. Safeguarding these facilities is necessary to protect everything from photos on social media to social security numbers.
Key takeaways:
- Attack methods differ by actor. Cyber espionage and cyberattacks on servers and their surrounding infrastructure — like cooling systems and business management software — are prioritized by nation states like Iran and China. Transnational criminal organizations and U.S.-based illicit actors engage in physical attacks to steal valuable machinery (sometimes for ransom) or disrupt and destroy data center operations.
- Close physical concentration is a significant vulnerability. The U.S hosts over 38% of data centers globally and clusters them close together — for example, northern Virginia alone has over 250. This makes it easier to attack in bulk and threatens data redundancy efforts. This occurred in spring 2026 when Iran attacked multiple Amazon Web Services sites in the United Arab Emirates and Bahrain, resulting in the failure of that region’s data redundancy plan.
- Public opinion about the sites could be weaponized. Symbolism is key for actors when choosing targets, and as negative sentiment around data centers grows, they are increasingly likely to be chosen. Additionally, actors may attempt to directly manipulate public opinion and sow domestic unrest around the sites to serve their long-term goals for political change. The authors stress that “the great majority of … opposition is lawful” and that conflating public opposition with terroristic or nation-state activities “is analytically unsound.”
- There is a public-private information sharing gap. Most data centers are privately owned and operated, and as such have commercial concerns when breaches happen — their reputation, shareholder liability, and regulatory penalties. Therefore, they’re less likely to report incidents, which can delay investigation and prosecution.
What they’re saying:
- Kevin Chenauthor
- “A modern data center has several layers an adversary can go after, and we found that different actors gravitate toward different ones depending on what they’re capable of and what they want.”
- Katrina McDermott, author
- “This white paper makes the case for treating data centers as critical infrastructure that must be secured.”
What’s next: This paper is the first in a series of expert insights on rapidly evolving, critical technology infrastructure emerging as threat risks.
Source: www.unomaha.edu




