Artificial Intelligence

Hackers Using AI to Target Siemens PLCs in Critical US Sectors

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

ICS security

Several government agencies in the United States have issued a joint cybersecurity advisory warning critical infrastructure organizations about hacker attacks targeting Siemens programmable logic controllers (PLCs).

According to the NSA, CISA, FBI, EPA, and DOE, the hackers are scanning the internet to identify exposed PLCs and developing exploits that could cause serious disruption to industrial processes. Other potential impacts include equipment damage, safety incidents affecting workers, compromise of sensitive data, and cascading effects on supply chains, associated facilities, and business operations.

The unidentified threat actors have targeted sectors such as energy, critical manufacturing, water and wastewater, food and agriculture, chemical, and commercial facilities. 

Targeted devices include the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series; for most of them, regardless of the CPU variant. 

The agencies said the attackers are using AI to create exploitation scripts for initial access, credential access, DoS attacks, and other purposes. The hackers can also exploit known vulnerabilities affecting the targeted PLCs.

Open source industrial automation libraries such as snap7.dll and python-snap7 are being combined with AI-made scripts to create malicious tools that mimic legitimate OT monitoring software. These tools enable the attackers to tamper with the memory of the targeted Siemens PLC, as well as configuration data and ladder logic programs.

Advertisement. Scroll to continue reading.

The advisory notes:

“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”

While the advisory says the described activity is an active threat rather than a theoretical risk, it does not mention any high-impact attacks observed in the wild. Instead, the agencies believe the threat actors are conducting “persistent reconnaissance” in preparation for future attacks that could be disruptive or destructive.

The advisory instructs organizations that use Siemens and other PLCs to ensure they have installed the latest patches, are isolated from the internet unless necessary, and have strong access controls. Security products that can monitor ICS environments for malicious activity are also recommended.

While the threat actors behind these attacks have not been named, the alert comes in the wake of a series of Iran-linked attacks aimed at the water sector in the United States. At least 12 US states have seen attacks targeting OT systems, but there are no confirmed cases of water supply disruptions. 

CISA has urged the water and wastewater sector to protect OT, particularly PLCs. Around the same time, the US government issued a warning about Iranian hackers targeting PLCs from Siemens, Schneider Electric, and Rockwell Automation. 

Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact

Related: Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

Related Content

Artificial Intelligence

Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores.

Artificial Intelligence

The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.

Artificial Intelligence

Anthropic has been conducting tests to identify issues in how AI agents interact with each other.

Artificial Intelligence

The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.

ICS/OT

CISA has also published several advisories describing vulnerabilities in ICS and other OT products.

Artificial Intelligence

Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.

Artificial Intelligence

Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue.

Artificial Intelligence

OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version