FBI and four US agencies warn AI tools are being used to hack Siemens PLCs in critical infrastructure

Five U.S. federal agencies have issued a joint cybersecurity advisory warning that threat actors are using AI-generated exploitation tools to attack Siemens S7 Series programmable logic controllers (PLCs) embedded in American critical infrastructure. The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency published the warning Wednesday as advisory AA26-231A, describing an active, ongoing campaign.
PLCs are industrial computers that automate physical processes in factories, power plants, water systems, and other critical facilities. Compromising them can cause equipment damage, extended downtime, or safety incidents that affect the public directly.
AI Is Lowering the Bar for ICS Attacks
According to the advisory, attackers are using AI to generate Python exploitation scripts that leverage the open-source snap7 library to communicate directly with Siemens S7 PLCs over the S7comm protocol. These custom tools provide read and write access to PLC memory, configuration data, and ladder logic programs — the code that dictates physical machinery behavior.
The tools are disguised as legitimate operational technology (OT) monitoring software, which makes them harder to detect on industrial networks. To locate targets, attackers use internet scanning services including Censys and ZoomEye to identify internet-exposed Siemens PLCs before deploying these tools.
Six Critical Infrastructure Sectors Targeted
The advisory identifies six primary target sectors: critical manufacturing, energy, water and wastewater systems, chemical, food and agriculture, and commercial facilities. The agencies also note that Siemens S7 PLCs are widely used across the defense industrial base, expanding the potential target set further.
The actively targeted device models include Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 series PLCs — a range that covers hardware both in active vendor support and long past end-of-life, significantly widening the attack surface.
Reconnaissance Now, Disruption Later
The agencies characterize the current activity as focused on persistent reconnaissance — gathering access and data rather than immediately disrupting operations. That framing suggests attackers are methodically preparing for potential future strikes on industrial systems, not simply probing opportunistically.
The warning follows a July incident in which hackers targeted more than 30 Minnesota water utilities, causing equipment malfunctions and forcing some facilities to switch temporarily to manual operations. CISA subsequently warned of a broader increase in cyberattacks against internet-exposed PLCs across U.S. water and wastewater infrastructure.
Organizations running Siemens S7 hardware are urged to take immediate action: inventory all PLCs on their networks, apply all available security patches, block any direct internet access to PLC devices, strengthen authentication and access controls, and monitor OT networks for unusual activity targeting S7 devices. The full advisory, as first reported by BleepingComputer, is available at CISA's advisory portal under reference AA26-231A.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source