Hackers Using AI to Target Siemens PLCs in Critical US Sectors
Hackers are using AI to target Siemens PLCs in US critical infrastructure sectors.
Summary
US agencies, including the NSA and CISA, have issued a joint advisory warning of hackers using AI to target Siemens PLCs in critical infrastructure sectors. The threat actors are scanning for exposed devices and developing exploits that could cause significant disruption, equipment damage, and safety incidents. While no high-impact attacks have been confirmed, agencies believe this is persistent reconnaissance for future disruptive or destructive attacks.
Full text
Several government agencies in the United States have issued a joint cybersecurity advisory warning critical infrastructure organizations about hacker attacks targeting Siemens programmable logic controllers (PLCs). According to the NSA, CISA, FBI, EPA, and DOE, the hackers are scanning the internet to identify exposed PLCs and developing exploits that could cause serious disruption to industrial processes. Other potential impacts include equipment damage, safety incidents affecting workers, compromise of sensitive data, and cascading effects on supply chains, associated facilities, and business operations. The unidentified threat actors have targeted sectors such as energy, critical manufacturing, water and wastewater, food and agriculture, chemical, and commercial facilities. Targeted devices include the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series; for most of them, regardless of the CPU variant. The agencies said the attackers are using AI to create exploitation scripts for initial access, credential access, DoS attacks, and other purposes. The hackers can also exploit known vulnerabilities affecting the targeted PLCs. Open source industrial automation libraries such as snap7.dll and python-snap7 are being combined with AI-made scripts to create malicious tools that mimic legitimate OT monitoring software. These tools enable the attackers to tamper with the memory of the targeted Siemens PLC, as well as configuration data and ladder logic programs.Advertisement. Scroll to continue reading. The advisory notes: “Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.” While the advisory says the described activity is an active threat rather than a theoretical risk, it does not mention any high-impact attacks observed in the wild. Instead, the agencies believe the threat actors are conducting “persistent reconnaissance” in preparation for future attacks that could be disruptive or destructive. The advisory instructs organizations that use Siemens and other PLCs to ensure they have installed the latest patches, are isolated from the internet unless necessary, and have strong access controls. Security products that can monitor ICS environments for malicious activity are also recommended. While the threat actors behind these attacks have not been named, the alert comes in the wake of a series of Iran-linked attacks aimed at the water sector in the United States. At least 12 US states have seen attacks targeting OT systems, but there are no confirmed cases of water supply disruptions. CISA has urged the water and wastewater sector to protect OT, particularly PLCs. Around the same time, the US government issued a warning about Iranian hackers targeting PLCs from Siemens, Schneider Electric, and Rockwell Automation. Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Related: Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Fortinet Acquires AI Security Company Virtue AIIrregular Details How a Naming Error Let AI Models Attack a Real Company Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating MalwareCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After DisclosureGoogle Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness GoalOver 1,000 Charities Hit by Beacon CRM Data BreachCybersecurity M&A Roundup: 21 Deals Announced in July 2026White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs Latest News Virtual Event Today: CodeSecCon – Secure Your Code and ApplicationsPrevalent AI Raises $22 Million to Expand Data Fabric PlatformUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities943 Patches Rolled Out With Oracle’s August 2026 Security UpdateChrome, Firefox Updates Patch Dozens of VulnerabilitiesCareCloud Data Breach Impact Grows to 3.7 Million Individuals Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDali Rajic is joining OpenAI as Chief Revenue Officer.Erika Dean has been appointed Chief Information Security Officer at Tricentis.C1 has named Jeff St. Clair Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — snap7.dll
- malware — python-snap7