AI attacks target critical infrastructure PLCs
US agencies warn of AI-powered attacks on Siemens PLCs in critical infrastructure
Five US federal agencies -- the NSA, CISA, FBI, Department of Energy, and EPA -- issued a joint advisory on August 19 warning that threat actors are actively using AI-generated exploitation scripts to target Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors. The advisory describes the activity as an "active threat," not a theoretical risk.
Attackers are using internet scanning services such as Censys and ZoomEye to find internet-exposed Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs. They then leverage AI coding assistants alongside open-source industrial automation libraries (snap7.dll and python-snap7) to create custom exploitation tools disguised as legitimate OT monitoring software. These tools provide read/write access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol.
The targeted sectors include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies also note that Siemens S7 PLCs are used in the Defense Industrial Base. While the advisory does not formally attribute the attacks, Iranian cyber operatives are suspected of being behind recent campaigns targeting water facilities across at least 12 US states, including a July attack that disrupted more than 30 community water systems in Minnesota.
The use of AI marks an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation tools. The feds urge organizations to immediately inventory all Siemens S7 PLCs, apply patches, block internet access to these devices, strengthen access controls, and monitor for anomalous S7comm behavior.