U.S. agencies warn of AI-assisted attacks against internet-exposed Siemens PLCs

Five U.S. federal agencies are warning that attackers are using artificial intelligence to develop tools aimed at internet-accessible Siemens S7 Series programmable logic controllers (PLCs) used acros...

Five U.S. federal agencies are warning that attackers are using artificial intelligence to develop tools aimed at internet-accessible Siemens S7 Series programmable logic controllers (PLCs) used across critical infrastructure.

The joint alert from the Cybersecurity and Infrastructure Security Agency, National Security Agency, FBI, Department of Energy and Environmental Protection Agency describes the activity as an “active threat.” The agencies did not attribute the intrusions to a specific group or government, although security researchers have linked related attacks against water and wastewater facilities to suspected Iran-affiliated operators.

AI lowers the barrier to OT attacks

According to the advisory, attackers are combining AI coding assistants with publicly available industrial automation libraries, including Snap7 and python-snap7. This enables them to create customized programs that imitate operational technology monitoring tools and interact with PLC memory, configuration information and ladder-logic programs through the S7comm protocol.

The resulting tools may support activities such as initial access, credential theft and denial-of-service attacks. The agencies said AI can shorten development time and reduce the specialized knowledge needed to build effective industrial-control-system attack chains.

Targets include exposed Siemens controllers in manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial environments. The alert also notes that similar equipment is used within the defense industrial base.

Exposure remains the central weakness

Researchers said attackers are locating vulnerable systems through internet-scanning services, then exploiting outdated software, weak security controls or default credentials. While AI increases attackers’ speed and flexibility, experts emphasized that publicly reachable PLCs and poorly segmented operational networks remain the underlying risk.

Organizations should inventory Siemens S7 devices, apply relevant updates and remove direct internet access. Recommended monitoring includes identifying S7comm connections from non-engineering workstations, unusual data-block access and write activity outside approved maintenance windows. Sequential scans of port 102, repeated connection attempts using changing parameters and unauthorized Snap7 library use may also signal reconnaissance or compromise.

Security specialists additionally recommend strong separation between IT and OT networks, tightly controlled remote access and one-way data-transfer mechanisms where appropriate. The agencies’ advisory contains further detection guidance and indicators for organizations investigating possible intrusions.