US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

US Cyber Agencies Sound Alarm on AI-Powered Attacks Targeting Critical Infrastructure

The US government has issued a joint advisory warning of an ongoing threat to critical infrastructure, as hackers are using artificial intelligence to develop custom tools that exploit vulnerabilities in Siemens PLCs. The attack vector is particularly concerning, given the potential for widespread disruption and even safety incidents.

PLCs, or programmable logic controllers, are industrial computers used to automate and control machinery and physical processes in factories and other critical infrastructure sectors. Siemens S7 Series PLCs are among those targeted, with hackers using AI-generated scripts to exploit vulnerabilities, outdated software, and weak authentication. The advisory warns that the attacks are not limited to Siemens PLCs, but rather represent a broader threat to all industrial computers used in critical infrastructure.

The affected sectors include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. Additionally, the Defense Industrial Base is also at risk due to the widespread use of Siemens S7 PLCs. Threat actors are using internet scanning services to identify exposed PLCs and then exploit critical vulnerabilities, leading to potential data theft, equipment damage, or extended downtime.

The AI-powered attacks involve custom tools disguised as legitimate OT monitoring software. These tools can provide read and write access to PLC memory, configuration data, and ladder logic programs over the S7comm protocol. The agencies warn that the attackers’ activity appears focused on persistent reconnaissance, potentially preparing for disruption to critical infrastructure.

Organizations are urged to take immediate action by inventorying their Siemens S7 PLCs, installing the latest security updates, blocking internet access, strengthening access controls, and monitoring for unusual activity targeting these devices. Given the increasing frequency of attacks against exposed PLCs at US critical infrastructure organizations, it is essential that companies prioritize industrial control system (ICS) security.

This joint advisory follows a recent surge in attacks targeting exposed PLCs at water utilities, including a coordinated attack on over 30 Minnesota water facilities in July. A similar warning was issued in April regarding Iranian-linked hackers targeting Rockwell Automation/Allen-Bradley PLCs. The threat landscape for industrial control systems is becoming increasingly complex, and it’s essential that companies stay vigilant to prevent potential disruptions.

In practical terms, organizations should take the following steps to mitigate this threat:

* Conduct a thorough inventory of all Siemens S7 PLCs in use

* Install the latest security updates and patches

* Block internet access to these devices unless absolutely necessary

* Strengthen access controls, including authentication and authorization measures

* Monitor for unusual activity targeting these devices

By taking proactive steps to secure their industrial control systems, organizations can reduce the risk of AI-powered attacks and protect their critical infrastructure from potential disruptions.


Source: Bleeping Computer — 2026-08-19