6 Sources
[1]
FBI: Hackers Are Targeting US Industrial and Water Systems With Help of AI
Hackers targeting US critical infrastructure, including energy and water providers, are using AI to help them break into vulnerable industrial IT systems, according to the FBI. On Wednesday, the FBI joined with several federal agencies, including the NSA, to warn the public about the "active threat," which has been targeting Siemens-developed industrial systems connected to the internet. The FBI is raising alarm bells, noting the hackers have been using AI to create "exploitation scripts" or malicious instructions written in computer code to help them hijack access to the internet-exposed industrial systems. The AI use has been able to do so by harnessing publicly available information about the Siemens systems to lead to "initial access, credential access, denial of service, and other objectives,' the alert says. "Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS (industrial control system) exploitation scripts and malicious tools," the FBI added. "In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures." For example, the AI-assisted scripting can create custom tools that pretend to mimic legitimate monitoring software on the industrial computers. The alert doesn't identify the AI used. But the threat underscores a growing trend of hackers, including state-sponsored groups, using AI programs to amplify their operations. This past summer, suspected Chinese hackers used open-source AI to create a "near-autonomous attack" capable of cracking 85 government accounts reportedly in Taiwan. In this case, the hackers have been targeting programmable logic controllers, or specialized computers used to control industrial systems. The FBI's alert flagged PLCs under the Siemens S7 Series used in the US. The danger covers a wide range of industries including manufacturing, food and agriculture and other commercial facilities, in addition to the energy and water sector. "This is not a theoretical risk -- it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems," the alert says. The warning seems related to a string of recent hacks that've been targeting water utility providers in at least 12 US states. Last month, the FBI warned the water utility hacks involved internet-exposed PLCs under the MicroLogix 1100 and 1400 series from Rockwell Automation/Allen-Bradley. The AI use may explain how the hackers have been able to quickly scale their efforts. Privately, the US suspects Iranian state-sponsored groups are likely behind the water utility hacks, according to The New York Times. In the meantime, the FBI's alert goes on to warn the hackers have been targeting Siemens PLCs set with "unconfigured (default) or minimally configured authentication." In response, the agency is urging the industry to apply patches and "ensure PLCs are NOT accessible from the Internet," among a host of other mitigation measures.
[2]
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities, in what five US federal agencies on Wednesday called an "active threat." In this latest round of intrusions against American critical infrastructure, the attackers use open source industrial automation libraries - specifically snap7.dll/python-snap7 - combined with AI coding assistants. Armed with the open source libraries and AI, the miscreants create custom tools that mimic operational technology (OT) monitoring software and provide read/write access to the PLC devices' memory, configuration data, and ladder logic programs via the S7comm protocol. "This is not a theoretical risk - it is an active threat," the feds warned. While the joint alert from the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA) doesn't attribute the threats to a particular government or criminal group, Iranian cyber operatives are suspected of being behind recent attacks targeting PLCs at water and wastewater facilities across at least 12 states, including a cyberattack that disrupted more than 30 community water systems in Minnesota in late July. "This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs," Cynthia Kaiser, Halcyon Ransomware Research Center SVP, told The Register. "Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society." National security and infosec experts last week told The Register that while there is no indication that the water-system hackers used AI in their intrusions, they worried that attackers would soon add AI to their arsenals for attacks against critical infrastructure. Now, that threat appears to be here. "What the advisory highlights with regard to AI usage aligns with what we've expected: state-sponsored adversaries are leveraging AI across the board for discrete tasks, like code checks and scripting, to scale their operations and move faster," Kaiser, a former FBI cyber division deputy assistant director, told us on Wednesday. "The advisory reflects the broader reality that threat actors are using AI to increase their efficiency." Siemens S7 Series PLCs under fire According to the Wednesday security alert, the latest attacks specifically target internet-exposed Siemens S7 Series PLCs across critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities - in other words: most of the critical industries providing goods and services that Americans use in their daily lives. "Additionally, Siemens S7 Series PLCs are used in other sectors, including the Defense Industrial Base (DIB), and could be targeted there as well," the feds warned. The Register reached out to the agencies for additional information about the attacks but did not receive any response to our questions. Attackers use internet-scanning services such as Censys and ZoomEye to find exposed, "poorly protected" PLCs running outdated software or using default passwords - and now they've got an AI boost. "Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives," the agencies said. "If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs." The use of AI also indicates "an evolution in threat actor capabilities," reducing the need for advanced technical knowledge about OT, and allowing the attacker to more rapidly develop working industrial control system malware and attack chains, the alert says. "I think that the bigger issue is still how exposed OT environments are," Benny Czarny, CEO and founder of critical infrastructure security firm Opswat, told The Register in an email. "AI makes it much easier for an attacker to create and modify scripts targeting PLCs, so the barrier to attacking industrial systems continues to fall. But for me the answer is not simply better AI detection." To mitigate this threat, the feds say critical infrastructure owners and operators should first - immediately - inventory all Siemens S7 Series PLCs in their environment, apply security patches as needed, and make sure no PLCs are accessible from the internet. It's also worth checking for anomalous S7comm behavior, including connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows, the feds suggest. Sequential IP scanning on port 102 and repeated connection attempts with varying parameters can indicate attackers conducting reconnaissance, and Snap7.dll library usage outside approved workstations may also indicate the presence of intruders on the network - so be sure to use these and the rest of the detection strategies detailed in the government security advisory to hunt for anomalies that may indicate a compromise. In addition to looking for indicators of compromise relevant to these intrusions, Czarny said it's critical to reduce the OT attack surface. "If data only needs to leave an OT network, use a data diode," he said. "There should be no network path back to the PLC for an attacker to exploit. Yes, AI makes this more urgent. But the real lesson for me is still the same: stop giving attackers a path to the critical system in the first place. And do not rely on antivirus and sandboxes to protect your data flow." ®
[3]
US warns Siemens devices can be hacked amid fears Iran is breaching water plants
Aug 19 (Reuters) - Several U.S. government agencies warned that unidentified hackers are trying to breach devices made by Siemens that are used to monitor and operate water facilities and other critical infrastructure systems, according to a cybersecurity advisory published Wednesday. The warning comes amid widespread cyber incidents targeting local water systems in multiple states in recent weeks in attacks cybersecurity experts suspect are linked to Iran. The advisory, opens new tab describes an "active threat" to all Siemens S7 Series programmable logic controllers across multiple critical infrastructure sectors, including manufacturing, energy, water and wastewater, chemical, food and agriculture facilities, according to the warning issued by the National Security Agency, FBI, Department of Energy, Environmental Protection Agency and the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency. Depending on specific circumstances, compromises of these devices could lead to disruption of critical processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations and cascading impacts across interconnected systems, the government warned. Siemens did not immediately respond to a request for comment. According to the advisory, the hackers are using AI to dramatically reduce the technical expertise and time required to develop exploits that can successfully compromise the systems, the agencies said. Reporting by AJ Vicens in Detroit; editing by Chris Sanders Our Standards: The Thomson Reuters Trust Principles., opens new tab * Suggested Topics: * Cybersecurity * Data Privacy * Water Management A.J. Vicens Thomson Reuters Cybersecurity correspondent covering cybercrime, nation-state threats, hacks, leaks and intelligence
[4]
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. PLCs are industrial computers used to automate and control machinery and physical processes in factories and other critical infrastructure. The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency issued the joint advisory Wednesday, saying the attacks are ongoing. "This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs)," reads the advisory. "However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems." The critical infrastructure sectors most targeted include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies also note that Siemens S7 PLCs are used in the Defense Industrial Base, which could also be targeted. Threat actors are using internet scanning services, including Censys and ZoomEye, to find exposed Siemens PLCs and exploit critical and high-severity vulnerabilities, outdated software, and weak authentication. The advisory says the attackers are using artificial intelligence to develop Python exploitation scripts that use the 'snap7.dll' and 'python-snap7' libraries to communicate with Siemens S7 PLC devices. These custom tools are disguised as legitimate OT monitoring software and can provide read and write access to PLC memory, configuration data, and ladder logic programs over the S7comm protocol. The agencies say the activity appears focused on persistent reconnaissance, potentially preparing attackers for disruption to critical infrastructure, including stealing sensitive data, damaging equipment, causing extended downtime, or leading to safety incidents. The actively targeted devices include Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs. Organizations are urged to inventory Siemens S7 PLCs, install the latest security updates, block internet access, strengthen access controls, and monitor for unusual activity targeting these devices. Today's advisory follows a recent increase in attacks targeting exposed PLCs at U.S. critical infrastructure organizations. In July, hackers targeted more than 30 Minnesota water utilities, causing equipment malfunctions and forcing some facilities to switch to manual operations temporarily. CISA later warned of an increase in attacks against internet-exposed PLCs used by water and wastewater utilities. Earlier in April, U.S. agencies also warned that Iranian-linked hackers were targeting internet-exposed Rockwell Automation/Allen-Bradley PLCs, causing disruptions and financial loss across multiple critical infrastructure sectors.
[5]
FBI Warns That Hackers Are Targeting Siemens Equipment Amid Recent Water Plant Breaches
Hackers are actively targeting Siemens equipment used in water plants and other critical infrastructure, several U.S. agencies are warning. The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), along with other agencies like the FBI, have issued a joint cybersecurity advisory this week detailing an active threat against Siemens S7 Series programmable logic controllers (PLCs). These controllers are industrial computers used to operate physical equipment and processes, including pumps and valves at water treatment facilities. "The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools," the advisory reads. According to the agencies, the attackers are using internet-scanning services to find Siemens PLCs that are exposed online and are running outdated software or are poorly protected. The sectors being targeted include manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. The agencies warn that a successful attack could disrupt critical industrial processes, create safety risks, damage equipment, cause downtime, or compromise sensitive operational data. Additionally, AI seems to be playing a role. The advisory says attackers are using AI to cut down on the technical expertise and time needed to develop exploits. Specifically, they are using AI-generated Python scripts to gain read and write access to Siemens PLCs while mimicking legitimate monitoring tools and avoiding detection. The warning comes amid a recent wave of cyberattacks against U.S. water systems. In July, the FBI and EPA warned that hackers were targeting internet-connected PLCs at water and wastewater facilities. At the time, water systems in at least seven states reported incidents to the FBI. Months earlier, CISA and other federal agencies had issued a separate warning that Iranian-affiliated hackers were actively targeting PLCs used in critical infrastructure. Minnesota was hit particularly hard. State officials said roughly 36 municipal water systems were attacked. President Donald Trump, however, downplayed the possibility that Iran was behind the Minnesota attacks and instead blamed the state and Gov. Tim Walz. "We heard in Minnesota there was a cyberattack and they blame it on Iran," Trump said in a televised cabinet meeting. "I don't think so. I blame it on Minnesota because they're grossly incompetent." The latest Siemens advisory adds to mounting warnings from the federal government over the vulnerability of critical infrastructure in the United States. Siemens did not immediately respond to a request for comment. The agencies recommend that operators take inventory of Siemens S7 Series PLCs, install critical security patches, make sure the controllers are not accessible from the internet, strengthen access controls, and monitor for suspicious activity.
[6]
US warns Siemens devices can be hacked amid fears Iran is breaching water plants
US agencies issued a warning about hackers targeting Siemens devices. These devices are crucial for operating water and other critical infrastructure systems. Hackers are reportedly using artificial intelligence to speed up attacks. This threat could disrupt essential services and damage equipment. The advisory highlights an active threat to multiple sectors across the nation. Several U.S. government agencies warned that unidentified hackers are trying to breach devices made by Siemens that are used to monitor and operate water facilities and other critical infrastructure systems, according to a cybersecurity advisory published Wednesday. The warning comes amid widespread cyber incidents targeting local water systems in multiple states in recent weeks in attacks cybersecurity experts suspect are linked to Iran. Also read: Trump declares 'Economic D-Day' against Iran, warns nations aiding Tehran of 'tremendous' consequences The advisory describes an "active threat" to all Siemens S7 Series programmable logic controllers across multiple critical infrastructure sectors, including manufacturing, energy, water and wastewater, chemical, food and agriculture facilities, according to the warning issued by the National Security Agency, FBI, Department of Energy, Environmental Protection Agency and the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency. Depending on specific circumstances, compromises of these devices could lead to disruption of critical processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations and cascading impacts across interconnected systems, the government warned. Siemens did not immediately respond to a request for comment. According to the advisory, the hackers are using AI to dramatically reduce the technical expertise and time required to develop exploits that can successfully compromise the systems, the agencies said.
Share
Copy Link
Five US federal agencies issued an urgent warning about hackers using AI-generated exploitation scripts to breach Siemens S7 Series programmable logic controllers at water facilities, energy providers, and manufacturing plants. The attacks have already disrupted over 30 water systems across 12 states, with Iranian state-sponsored groups suspected.
The FBI, NSA, CISA, Department of Energy, and Environmental Protection Agency issued a joint cybersecurity advisory Wednesday warning of an "active threat" targeting critical infrastructure across the United States
1
. Hackers are using AI-powered attacks to breach Siemens S7 Series programmable logic controllers at water facilities, energy providers, manufacturing plants, and other essential services. "This is not a theoretical risk -- it is an active threat," federal agencies emphasized in their warning2
. The advisory marks a concerning evolution in cyber warfare, as attackers leverage artificial intelligence to dramatically reduce the technical expertise and time required to develop working industrial control system exploitation tools.
Source: BleepingComputer
Threat actors are using AI-generated exploitation scripts to create custom tools that mimic legitimate operational technology monitoring software
4
. These Python scripts utilize open-source industrial automation libraries, specifically snap7.dll and python-snap7, combined with AI coding assistants to provide read and write access to Siemens PLCs' memory, configuration data, and ladder logic programs via the S7comm protocol2
. The AI assistance enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures while avoiding detection. Hackers are using internet-scanning services including Censys and ZoomEye to identify internet-exposed industrial control systems running outdated software or using default passwords4
.
Source: Gizmodo
The attacks have already caused significant disruption to water utility providers across at least 12 states. In late July, cyberattacks on water systems disrupted more than 30 community water systems in Minnesota alone
2
, causing equipment malfunctions and forcing facilities to switch to manual operations temporarily4
. The targeted sectors extend beyond water and wastewater systems to include critical manufacturing, energy, chemical, food and agriculture, and commercial facilities3
. Siemens S7 Series PLCs are also used in the Defense Industrial Base, which could be targeted as well2
. Depending on specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems1
.
Source: PC Magazine
Related Stories
While the joint cybersecurity advisory does not officially attribute the breaching water plants attacks to a specific nation-state, Iranian state-sponsored groups are suspected of being behind the recent intrusions
2
. According to The New York Times, the US privately suspects Iranian operatives are likely responsible for the water utility hacks1
. "This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs," said Cynthia Kaiser, Halcyon Ransomware Research Center SVP and former FBI cyber division deputy assistant director2
. Earlier in April, US agencies warned that Iranian-linked hackers were targeting internet-exposed Rockwell Automation/Allen-Bradley PLCs, causing disruptions and financial loss across multiple critical infrastructure sectors4
.Federal agencies are urging critical infrastructure owners and operators to immediately inventory all Siemens S7 Series programmable logic controllers in their environment, including S7-200, S7-300, S7-400, S7-1200, and S7-1500 models
4
. Organizations must apply security patches and ensure PLCs are not accessible from the internet1
. The advisory recommends strengthening access controls, monitoring for anomalous S7comm protocol behavior including connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows2
. "The advisory reflects the broader reality that threat actors are using AI to increase their efficiency," Kaiser noted, highlighting how state-sponsored adversaries are leveraging AI across the board for discrete tasks like code checks and scripting to scale their operations and move faster2
. The threat activity appears focused on persistent reconnaissance, potentially preparing attackers for future disruption to critical infrastructure operations4
.Summarized by
Navi
[2]
[4]
30 Apr 2025•Technology

11 Mar 2026•Technology

22 Jun 2026•Policy and Regulation

1
Technology

2
Technology

3
Technology
