13 Sources
[1]
US says hackers are targeting vulnerable water systems with the help of AI
Amidst a spate of ongoing cyberattacks targeting water systems across the country, the U.S. government's security agencies are warning that hackers are actively breaking into Siemens devices used in critical infrastructure. U.S. cybersecurity agency CISA, the FBI, and the National Security Agency,
[2]
US authorities say Siemens controllers used for water and other infrastructure are being targeted by hackers -- agencies claim threat actors use AI tools to generate exploitation scripts
Attacks on these industrial controllers could lead to sabotage of critical infrastructure. Various U.S. agencies just released a warning claiming that Iranian hackers are targeting Siemens S7-series programmable logic controllers (PLCs). According to the Cybersecurity and Infrastructure Security
[3]
FBI: Hackers Are Targeting US Industrial and Water Systems With Help of AI
Hackers targeting US critical infrastructure, including energy and water providers, are using AI to help them break into vulnerable industrial IT systems, according to the FBI. On Wednesday, the FBI joined with several federal agencies, including the NSA, to warn the public about the "active
[4]
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities, in what five US federal agencies on Wednesday called an "active threat." In this latest round
[5]
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and
[6]
US warns Siemens devices can be hacked amid fears Iran is breaching water plants
Aug 19 (Reuters) - Several U.S. government agencies warned that unidentified hackers are trying to breach devices made by Siemens that are used to monitor and operate water facilities and other critical infrastructure systems, according to a cybersecurity advisory published Wednesday. The warning
[7]
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. PLCs are industrial computers used to automate and control machinery and physical processes in factories and other
[8]
FBI Warns That Hackers Are Targeting Siemens Equipment Amid Recent Water Plant Breaches
Hackers are actively targeting Siemens equipment used in water plants and other critical infrastructure, several U.S. agencies are warning. The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), along with other agencies like the FBI, have issued a joint
[9]
Hackers are using "evolved" capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale -- "active threat" currently hitting energy, water and agricultural industries
* Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture * Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool * The identity of the
[10]
U.S. agencies warn AI-powered attacks on Siemens PLCs at water plants
The NSA, CISA, FBI, and other agencies say threat actors are using AI-generated scripts to target Siemens controllers across critical infrastructure sectors Five federal agencies -- the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency -- jointly warned Wednesday that
[11]
'This is not a theoretical risk -- it is an active threat': The NSA, FBI, CISA and more warn of AI-assisted hacks against critical US infrastructure and facilities
Energy, water management, manufacturing facilities and more are said to be vulnerable. A cybersecurity advisory jointly authored by multiple US agencies, including the NSA, CISA, FBI, DOE, and EPA, warns the owners and operators of industrial facilities of an "active cyber threat" to Siemens S7
[12]
US warns Siemens devices can be hacked amid fears Iran is breaching water plants
US agencies issued a warning about hackers targeting Siemens devices. These devices are crucial for operating water and other critical infrastructure systems. Hackers are reportedly using artificial intelligence to speed up attacks. This threat could disrupt essential services and damage equipment.
[13]
US authorities warn of cyberattacks targeting Siemens controllers
In recent weeks, numerous cyberattacks on local water supply systems had been recorded in several US states. Minnesota alone reported 30 cyberattacks on a water utility over two days in late July. Experts suspect the attacks are linked to Iran, even though US President Donald Trump said he did not
Share
Copy Link
US cybersecurity agencies issued an urgent warning that hackers are using AI-generated exploit scripts to breach Siemens S7 programmable logic controllers across critical infrastructure sectors. The attacks have targeted vulnerable water systems in at least 12 states, with Iranian hackers suspected behind the escalating campaign against internet-exposed industrial control systems.
US cybersecurity agencies including CISA, the FBI, and the NSA issued a joint advisory warning of an "active threat" targeting critical infrastructure nationwide. Hackers are exploiting Siemens S7 programmable logic controllers used to control automated physical processes across energy, water systems, manufacturing, chemical facilities, food and agriculture, and commercial operations
1
2
. The Department of Energy and Environmental Protection Agency co-authored the warning, underscoring the severity of the situation4
.The attacks specifically target all variants of the Siemens S7 Series, including S7-200, S7-300, S7-400, S7-1200, and S7-1500 models
5
. Attackers leverage internet scanning services like Censys and ZoomEye to identify internet-exposed industrial control systems running outdated software or protected with default passwords4
. CISA emphasized this represents a real-world threat, not a theoretical scenario, with potential consequences including disruption of critical industrial processes, safety incidents, equipment damage, and cascading impacts across interconnected systems2
.
Source: BleepingComputer
Hackers are using AI-generated exploit scripts to dramatically reduce the technical expertise and time required to develop working attacks against programmable logic controllers
3
. The AI-assisted attacks harness publicly available information about Siemens S7 PLC systems to achieve initial access, credential access, denial of service, and other malicious objectives5
.Threat actors deploy custom Python scripts incorporating open-source industrial automation libraries like snap7.dll and python-snap7, combined with AI coding assistants
4
. These tools mimic legitimate OT monitoring software while providing read/write access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol5
. An incident response professional noted the significance of hackers using AI not just to identify vulnerable systems but to understand how these devices operate1
.
Source: Hacker News
The use of AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures implemented by operators
3
. This represents an evolution in threat actor capabilities, allowing them to create custom tools that behave like legitimate monitoring software, making detection more challenging2
.The warning follows escalating cyberattacks by suspected Iranian hackers targeting vulnerable water systems and wastewater providers across at least 12 states
3
4
. Officials reported intrusions at water facilities in Minnesota, Michigan, Arkansas, Georgia, and New Jersey1
. A cyberattack in late July disrupted more than 30 community water systems in Minnesota alone4
.Cynthia Kaiser, former FBI cyber division deputy assistant director and current SVP at Halcyon Ransomware Research Center, stated that Iran-affiliated actors are actively targeting operational technology because programmable logic controllers underpin essential health, safety, and critical infrastructure across society
4
. While the joint advisory does not officially attribute the attacks, the US privately suspects Iranian state-sponsored groups are behind the water utility hacks3
.CISA has repeatedly warned critical infrastructure owners to keep industrial control systems disconnected from the internet, acknowledging that rural communities face disproportionate risk because these systems service large geographic areas
1
. The attacks have escalated since Iranian hackers first began targeting internet-exposed systems used in critical infrastructure1
.
Source: PC Magazine
Related Stories
The threat extends beyond US borders. A recent investigation revealed a near-autonomous attack targeting government entities in Taiwan, where Chinese-language operators deployed AI-powered frameworks built on Hermes and OpenClaw agents
5
. Between July 1-4, 2026, attackers launched 12 attack waves using up to eight lettered sub-agents running in parallel to automate reconnaissance, crack government employee credentials, conduct data exfiltration, and install persistent backdoors5
.Kaiser emphasized that state-sponsored adversaries are leveraging AI across discrete tasks like code checks and scripting to scale operations and accelerate attack timelines
4
. Benny Czarny, CEO of critical infrastructure security firm Opswat, noted that while AI makes it easier for attackers to create and modify scripts targeting PLCs, the fundamental issue remains how exposed OT environments are to begin with4
.The proliferation of internet-connected devices in critical infrastructure has created prime targets for both financially motivated hackers and nation-states seeking strategic advantages through cyber warfare
2
. Federal agencies recommend operators immediately inventory all Siemens S7 Series PLCs, apply security patches, ensure no devices are accessible from the internet, implement strong access controls, and deploy cybersecurity monitoring for anomalous S7comm behavior4
5
.Summarized by
Navi
[4]
02 Sept 2026•Technology

13 Nov 2025•Technology

11 Mar 2026•Technology

1
Technology

2
Technology

3
Science and Research
