Five US government agencies have issued an urgent joint advisory warning that hackers are actively targeting Siemens S7 Series programmable logic controllers using AI-generated exploitation scripts disguised as legitimate monitoring tools.
The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency released the advisory on August 18 after confirming an active campaign against industrial control systems across the United States. The agencies said threat actors are scanning the internet for exposed Siemens S7 controllers running outdated software and deploying AI-crafted scripts to exploit them.
Water systems in the crosshairs
The targeted sectors include critical manufacturing, energy, water and wastewater, chemicals, food and agriculture, and commercial facilities. The warning comes amid a broader wave of cyberattacks on US water infrastructure that began earlier this year, with Minnesota reporting at least 30 incidents involving local water systems in late July alone.
A joint CISA advisory in late July linked those water system intrusions to Iranian-affiliated hackers exploiting industrial equipment made by Siemens, Rockwell Automation, and Schneider Electric. While the federal agencies have stopped short of formally attributing the current Siemens S7 campaign to Iran, the overlap in targets and timing has drawn attention from security researchers.
AI makes the attacks faster and harder to detect
The advisory highlighted a significant shift in attacker methodology. Threat actors are using AI to generate exploitation scripts that appear to be legitimate diagnostic or monitoring tools, making them harder to detect through standard security monitoring. The scripts leverage publicly available information about Siemens PLC configurations to identify vulnerable installations.
CISA said exploitation could lead to disruption of critical industrial processes, safety incidents, equipment damage, downtime, compliance violations, and cascading impacts across interconnected systems. The agencies emphasized this is not a theoretical risk but an active and ongoing threat.
Siemens responded on August 19, stating it had not detected an increased level of attacks or any previously unknown vulnerabilities in its products. However, the joint advisory applies broadly to all PLC owners and operators, noting that the targeting extends beyond Siemens hardware alone.
Operators urged to disconnect PLCs from internet
The top mitigations include conducting an immediate inventory of all Siemens S7 Series PLCs, applying critical security patches, ensuring the devices are not accessible from the internet, strengthening access controls, monitoring for unauthorized activity, and hardening PLC services, protocols, and ladder logic integrity.
Water utilities have been especially vulnerable because many small and mid-size systems rely on internet-connected PLCs for remote monitoring and management. The Water Information Sharing and Analysis Center issued its own alert on August 20, urging members to implement the recommended hardening steps immediately.
The advisory came as US-Iran tensions escalated over the Strait of Hormuz and broader regional conflict, with cybersecurity officials warning that state-sponsored campaigns against US critical infrastructure could intensify. The agencies said the threat remains active and urged organizations to prioritize the recommended mitigations without delay.
discussion