Cybersecurity agencies in the US have issued a joint warning about AI-powered attacks on Siemens PLCs in critical infrastructure. The threat is real and ongoing, with potential consequences that go far beyond mere disruption.
Siemens PLCs are industrial computers used to automate and control machinery and physical processes in factories, power plants, water treatment facilities, and other critical infrastructure sites. They’re ubiquitous in the US, found in over 30 sectors including manufacturing, energy, transportation, and more. The attackers, however, aren’t just targeting Siemens devices – they’re after any industrial computer that can be exploited for their purposes.
Threat actors are using internet scanning services to find exposed PLCs, then exploiting critical vulnerabilities, outdated software, and weak authentication to gain access. But here’s where it gets sinister: the attackers are using artificial intelligence to develop custom Python scripts that communicate with Siemens S7 PLC devices over the S7comm protocol. These tools disguise themselves as legitimate OT monitoring software, providing the attackers with read and write access to PLC memory, configuration data, and ladder logic programs.
The agencies warn that this activity appears focused on persistent reconnaissance – essentially, gathering intelligence about the target systems before potentially causing disruption or damage. The consequences could be catastrophic: stealing sensitive data, damaging equipment, causing extended downtime, or even leading to safety incidents. We’ve seen it happen already in July when hackers targeted more than 30 Minnesota water utilities, and earlier this year when Iranian-linked hackers went after Rockwell Automation/Allen-Bradley PLCs.
The joint advisory from the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency urges organizations to take immediate action. They need to inventory their Siemens S7 PLCs, install the latest security updates, block internet access to these devices, strengthen access controls, and monitor for unusual activity targeting these systems.
It’s a sobering reminder that critical infrastructure is under attack, and it’s not just about preventing data breaches or ransomware attacks. It’s about ensuring the safety of people and communities, and maintaining the integrity of our industrial processes. The agencies’ warning should serve as a wake-up call for organizations to prioritize PLC security – and to assume that any exposed device could be compromised at any moment.
Ultimately, this is a stark illustration of how advanced threat actors are leveraging AI to evade detection and wreak havoc on critical infrastructure. As we continue to rely more heavily on connected industrial systems, the stakes will only grow higher. It’s time for organizations to get serious about PLC security – before it’s too late.
Source: Bleeping Computer — 2026-08-19