U.S. agencies warned hackers are using AI to attack Siemens industrial controls at water plants

U.S. agencies warned hackers are using AI to attack Siemens industrial controls at water plants

Published 26 days ago

Free daily briefing on global business news.

The NSA, CISA, FBI, and other agencies say threat actors are using AI-generated scripts to target Siemens controllers across critical infrastructure sectors

Five federal agencies — the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency — jointly warned Wednesday that unknown hackers are actively probing Siemens S7 Series programmable logic controllers deployed throughout U.S. critical infrastructure and leveraging artificial intelligence to craft exploitation scripts that masquerade as legitimate monitoring tools.

Sectors identified as targets include critical manufacturing, energy, water and wastewater systems, chemical, food and agriculture, and commercial facilities, the agencies said. Siemens S7 Series PLCs — industrial computers that automate and control machinery and physical processes — are also used in the Defense Industrial Base, which the agencies said could be targeted as well.

The advisory states that hackers have been leveraging internet scanning services such as Censys and ZoomEye to identify Siemens PLCs that are exposed online and running outdated software or configured with weak authentication. They are then deploying AI-built Python scripts that leverage the snap7.dll library to obtain read and write access to PLC memory, configuration data, and ladder logic programs through the S7comm protocol. The tools are disguised as legitimate operational technology monitoring software to evade detection.

The agencies said that AI-assisted script generation marks a shift in how attackers operate, lowering the skill threshold and accelerating the pace at which functional exploits can be built. The activity is assessed as likely intended to position threat actors to cause operational disruptions to critical infrastructure.

The targeted Siemens devices span multiple product generations, including S7-200, S7-300, S7-400, S7-1200, and S7-1500 series controllers. Should attackers gain unauthorized access, the agencies cautioned that the consequences could range from halted industrial operations and safety emergencies to hardware failures, exposure of sensitive data, and failures that ripple through connected infrastructure.

The advisory called on organizations to catalog their Siemens S7 Series PLCs, patch known vulnerabilities, remove the devices from public internet exposure, tighten access controls, and establish monitoring for suspicious activity. The agencies said organizations that rely on third-party service providers or system integrators for remote PLC access should share the advisory with those parties, as asset owners may not realize their systems are exposed.

The warning comes amid a broader increase in attacks targeting internet-exposed PLCs, according to Reuters. A July attack struck more than 30 water utilities across Minnesota, triggering equipment malfunctions and compelling some facilities to fall back on manual operations, according to BleepingComputer. Siemens did not respond to a request for comment.

Join 500,000+ readers who start their day with Quartz.

By subscribing, you agree to our Terms of Service and Privacy Policy.

Global business news for a smarter world

© 2026 Quartz Media, Inc. All rights reserved.