US Agencies Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs in Critical Infrastructure

On August 19, 2026, CISA, the NSA, the FBI, the Department of Energy and the EPA issued a joint cybersecurity advisory warning that threat actors are actively using artificial-intelligence-generated exploit scripts against Siemens S7 Series programmable logic controllers (PLCs) used across U.S. critical infrastructure. The agencies characterized the campaign as an active, ongoing threat rather than a theoretical risk, targeting the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities sectors.

According to the advisory, attackers are using internet-scanning services such as Censys and ZoomEye to locate internet-exposed Siemens PLCs running outdated firmware or lacking adequate protections. The AI-generated scripts, disguised as legitimate monitoring tools, communicate with the controllers over the S7comm protocol, giving attackers the ability to read and write PLC memory, alter configuration data, and modify the ladder-logic programs that govern physical industrial processes. Officials reported that at least 12 U.S. states have seen related activity, including an incident in Minnesota that disrupted operations at more than 30 community water systems.

The advisory notes that this type of AI-assisted reconnaissance and exploit development is not confined to Siemens equipment and is likely to extend to other PLC vendors over time, reflecting a broader trend of attackers using generative AI tools to lower the technical barrier for compromising operational technology. CISA is urging asset owners to isolate PLCs from the public internet, apply available firmware updates, enforce strong authentication on engineering interfaces, and monitor S7comm traffic for anomalous read/write activity.

Read the original report →