Five U.S. federal agencies issued a joint advisory warning that threat actors are actively using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers deployed across American critical infrastructure1,2.
The advisory, authored by the National Security Agency, Cybersecurity and Infrastructure Security Agency, FBI, Department of Energy, and Environmental Protection Agency, describes the attacks as ongoing. The targeted sectors include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies noted that Siemens S7 Series PLCs are also used in the Defense Industrial Base, which could face targeting as well.
Attackers are using internet scanning services, including Censys Technologies Corporation and ZoomEye, to locate exposed Siemens PLCs and exploit critical and high-severity vulnerabilities, outdated software, and weak authentication. The AI component is specific: threat actors are using artificial intelligence to develop Python exploitation scripts that leverage the snap7.dll and python-snap7 libraries to communicate with Siemens S7 Series PLC devices over the S7comm protocol.
The custom tools are disguised as legitimate OT monitoring software and can provide read and write access to PLC memory, configuration data, and ladder logic programs. The actively targeted devices span the Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs.
The advisory characterizes the activity as focused on persistent reconnaissance, but warns it could be preparing attackers for disruption to critical infrastructure, including stealing sensitive data, damaging equipment, causing extended downtime, or leading to safety incidents. The advisory also stated that ongoing PLC targeting activity extends beyond Siemens PLCs, urging all PLC owners and operators to apply relevant mitigations.
Recommended mitigations include inventorying Siemens S7 Series PLCs, installing the latest security updates, blocking internet access to the devices, strengthening access controls, and monitoring for unusual activity targeting these controllers.
The advisory follows a pattern of escalating PLC-focused attacks. In July, hackers targeted more than 30 Minnesota water utilities, causing equipment malfunctions and forcing some facilities to switch to manual operations temporarily. Cybersecurity and Infrastructure Security Agency subsequently warned of an increase in attacks against internet-exposed PLCs used by water and wastewater utilities. In April, U.S. agencies warned that Iranian-linked hackers were targeting internet-exposed Rockwell Automation/Allen-Bradley PLCs, causing disruptions and financial loss across multiple critical infrastructure sectors.
ANALYSIS The explicit identification of AI-generated exploitation tooling marks a shift in how federal agencies characterize OT threats — the concern is no longer hypothetical use of AI in cyberattacks but documented, active deployment against physical-process controllers. The breadth of targeted PLC models, spanning legacy S7-200 through current S7-1500 units, indicates that both aging and modern industrial installations are exposed. The advisory's note that the threat extends beyond Siemens PLCs suggests the AI-assisted exploitation methodology is transferable across vendors, widening the attack surface for the entire industrial control ecosystem.