AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
NSA, CISA, FBI, DOE and EPA warn hackers are using AI-generated scripts to actively attack Siemens S7 PLCs across critical-infrastructure sectors.
A joint cybersecurity advisory from the NSA, CISA, FBI, Department of Energy and EPA warns of an active threat campaign targeting water, food, energy, chemical, manufacturing and commercial facilities via Siemens S7 Series programmable logic controllers. The actors use internet scanning to find exposed or poorly protected PLCs, then deploy AI-generated exploitation scripts disguised as legitimate monitoring tools, an OT first that dramatically lowers the expertise required for ICS attacks. Siemens says no new S7 vulnerabilities are involved, only exploitation of misconfigurations, and it is coordinating with CISA's ProductCERT. The warning follows a joint FBI-EPA advisory confirming attacks at water and wastewater utilities in at least 12 states since July 27.
- Advisory calls the attacks an 'active threat' that could disrupt industrial processes or compromise data.
- First CISA cybersecurity advisory to flag AI-generated scripts for ICS/OT exploitation.
- Siemens says no new S7 vulnerabilities; attackers exploit misconfigurations and outdated software.
- Scans found 4,400 internet-exposed PLCs, including 22 in recently targeted cities.
Full article951 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first.
Listen to this article
0:00
Learn more.
Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday.
It’s the latest government warning about attacks on critical infrastructure as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems— but doesn’t mention in Wednesday’s alert.
The National Security Agency didn’t immediately respond to a request for comment about who was behind the attacks on the PLCs, which are used to control manufacturing processes.
The agencies said the attacks were an “active threat,” rather than a theoretical one. The attacks could disrupt critical industrial processes, cause safety incidents or lead to the compromise of sensitive data.
Wednesday’s alert from the NSA, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department and Environmental Protection Agency makes special note of the hackers using AI-generated exploitation scripts in the attacks.
“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the alert states. “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”
A former top CISA official, Michael Garcia, thought that it was a first for the agency in one of its cybersecurity advisories (CSAs) about operational technology (OT).
“It is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems,” Garcia, now vice president of the cybersecurity practice at Monument Policy Advocacy, said on LinkedIn. But the advisory doesn’t recommend using AI in response, instead focusing on well-known, traditional defensive measures, he added.
Frenos, an OT penetration testing company, found another element of the alert troubling: The method by which the attackers could use the approach beyond Siemens-made PLCs.
“Siemens S7 is the subject here, but the exposure pattern is not brand specific,” Brian Proctor, CEO of the company, said in an email. “An adversary who has mapped your data blocks understands your process. They know what normal looks like, which means they know what an operator would fail to notice.”
The AI-generated scripts are disguised as legitimate monitoring tools, the advisory said of the hackers behind them.
“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the advisory reads.
Siemens said it was “aware” of the alert and “is coordinating closely with CISA.”
“This advisory does not describe new vulnerabilities within the S7 Series programmable logic controllers (PLC). Instead, this reflects threat actors employing new techniques to exploit potential misconfigurations,” the company continued, noting a security bulletin it issued last month.
“Siemens will provide updates around this issue to potentially affected customers through our ProductCERT team,” it said. “At this point in time, we have not identified increased attack levels or unknown vulnerabilities in Siemens ICS products.”
Updated 8/20/2026: to include Siemens comment.
More Scoops
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks.
Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn
After major Poland energy grid cyberattack, CISA issues warning to U.S. audience
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/