Multiple U.S. federal agencies, including CISA, the FBI, the NSA, the Department of Energy, and the EPA, issued a joint advisory on Wednesday warning of an active threat targeting Siemens S7 Series programmable logic controllers (PLCs) used in critical infrastructure. The advisory says hackers are using internet-scanning services to find exposed PLCs running outdated software or otherwise poorly protected, and are leveraging AI tools to generate exploitation scripts that can mimic legitimate monitoring tools . The targeted sectors include manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities . A successful attack could disrupt critical processes, cause safety incidents, equipment damage, downtime, or compromise sensitive data .
The use of AI is a notable escalation. According to the advisory, attackers are using AI-generated Python scripts to gain read and write access to Siemens PLCs while evading detection . An incident response professional told TechCrunch that while the use of AI is noteworthy, these devices are already highly vulnerable .
The warning comes amid a wave of cyberattacks on U.S. water systems, with incidents reported in Minnesota, Michigan, Arkansas, Georgia, and New Jersey . Federal officials have not formally attributed these attacks to Iran, and President Trump has downplayed Iranian involvement, blaming Minnesota instead . Siemens said it had not detected an increased level of attacks or any previously unknown vulnerabilities, but is coordinating with CISA .
Agencies recommend that operators inventory their Siemens S7 PLCs, install critical patches, ensure controllers are not internet-accessible, strengthen access controls, and monitor for suspicious activity .
