Cyberattackers are using AI to find vulnerable Siemens PLCs, US warns

A group of US government agencies have issued a warning of an active cyberthreat to US-based Siemens S7 series PLCs in which the attackers are using AI-generated scripts, disguised as legitimate monitoring tools, to find Internet-exposed PLCs that are poorly protected or running outdated software. They say that this use of AI represents “an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools”.
In addition, AI allows the attackers to leverage additional attack vectors rapidly, and to adapt to defensive measures. The threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.
The agencies warn that exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,.
“If PLCs are exposed to the Internet, they are at high risk for exploitation,” they say. “This is not a theoretical risk – it is an active threat.”
The agencies – which include the NSA (National Security Agency), Cisa (Cybersecurity and Infrastructure Security Agency), FBI (Federal Bureau of Investigation), DoE (Department of Energy) and the EPA (Environmental Protection Agency) – recently issued another warning about cyberattacks by “Iran-affiliated cyber-actors” on PLCs used in critical infrastructure applications. This warning was followed by news of cyberattacks on water utilities in at least seven US states. The new warning does not identify the potential attackers, but says that the Siemens PLC risks are “one subset of a wider threat landscape”.
The agencies are urging all owners and operators of OT (operational technology) systems that use Siemens S7 series and other PLC devices to check that their systems:
- are properly protected with all applicable security patches and updates,
- are isolated from the Internet wherever possible, and
- have strong access controls, and employ security tooling to monitor ICS environments for anomalous or malicious activity.
They say that these mitigations are particularly important for owners and operators who work with third-party service providers or systems integrators who may have remote access to their PLCs, because the owners may not realise that their systems are exposed and at risk.
The cyberattackers are said to be actively targeting the following Siemens PLCs:
- S7-200 Series
- S7-300 Series (all variants including 314, 315, 317 models)
- S7-400 Series
- S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)
- S7-1500 Series (all CPU variants, including F-series safety controllers)
According to the agencies, the attackers are:
- Using Internet scanning services to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs
- Rapidly iterating exploit code through AI-assisted development, lowering technical barriers to ICS (industrial control system) attacks
- Taking advantage of insecure credentials to access exposed devices that have unconfigured (default) or minimally configured authentication
- Deploying AI-generated Python scripts that incorporate the snap7.dll library from public repositories to gain read/write access to the PLC and to mimic legitimate tools
- Masquerading malicious scripts as legitimate monitoring tools to evade detection by security teams
- Conducting read/write operations on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations
The agencies says that this activity pattern is likely intended to be persistent reconnaissance in targeted sectors and facilities, allowing them to develop capabilities and prepare to attack critical infrastructure. The actors are testing and refining their exploitation techniques on specific PLC models to improve their ability to compromise the controllers. They are leveraging read access to understand target environments, enabling them to prepare and position themselves for future write operations that could cause disruption or other operational impacts.
Unauthorised access to PLCs could result in:
- Disruption of critical industrial processes affecting production throughput, product quality, and public services
- Safety incidents affecting personnel through manipulation of safety interlocks, emergency shutdown systems, or process parameters
- Equipment damage and extended operational downtime from process upsets, improper sequencing, or forcing equipment to operate outside of its design parameters
- Compromise of sensitive operational data, including proprietary process recipes, control strategies, and facility configurations
- Cascading impacts across interconnected systems affecting supply chains, dependent facilities, and integrated business operations
- Regulatory compliance violations and potential liability from process safety management failures.
The US government agencies are urging organisations to protect and defend their PLCs using comprehensive defence-in-depth strategies, as well as CVE (Common Vulnerabilities and Exposures) remediation. They should implement detection strategies and hunt for anomalies that may indicate a compromise, focusing on:
- Anomalous S7 communications behaviour: Connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows
- Reconnaissance indicators: Sequential IP scanning on port 102, repeated connection attempts with varying parameters, or enumeration of CPU properties
- Tool artifacts: Snap7.dll library usage outside approved engineering workstations, Python scripts with S7comm functionality, or unauthorised monitoring software installations
- Temporal anomalies: S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting rather than human operators, or configuration changes without corresponding work orders or change tickets
- Geographic anomalies: Connections originating from unexpected countries or IP ranges not associated with vendors or integrators.
The top mitigations recommended by the agencies include:
- Inventory all Siemens S7 PLCs
- Apply critical security patches
- Ensure PLCs are not accessible from the Internet
- Strengthen access controls
- Monitor for unauthorised activity
- Harden PLC services, protocols, and ladder logic integrity
- Hunt for anomalies that may indicate a compromise

