Posted in

U.S. Warns of AI-Assisted Attacks Targeting Siemens PLCs and Critical Infrastructure

U.S. federal agencies have warned of an active cyber threat targeting critical infrastructure organizations with the help of artificial intelligence (AI)-generated exploitation scripts.

The activity has targeted Siemens S7 Series Programmable Logic Controllers (PLCs) as threat actors conduct reconnaissance and develop attack capabilities using AI-generated scripts disguised as legitimate industrial monitoring tools.

However, federal agencies said the campaign appears to extend beyond Siemens PLCs and could pose a broader threat to industrial control systems (ICS) deployed across critical infrastructure sectors.

The warning was issued jointly by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA).

According to the agencies, attackers are using internet-scanning services such as Censys and ZoomEye to locate exposed PLCs running outdated software or protected by inadequate security controls.

Critical Infrastructure Sectors Under Target

The activity has been observed targeting organizations across several critical infrastructure sectors, including:

Critical Manufacturing
Energy
Water and Wastewater Systems
Chemical
Food and Agriculture
Commercial Facilities

The agencies have not attributed the activity to any known threat actor or cybercrime group.

Compromising poorly secured PLCs could have serious consequences, including disruption of industrial processes, equipment damage, operational downtime, safety incidents, exposure of sensitive information, and compliance violations.

Because industrial environments are often interconnected, an intrusion affecting one system could potentially have cascading effects across other operational technology (OT) environments.

Siemens S7 PLCs Targeted

The agencies said the observed activity has specifically targeted several Siemens S7 PLC product lines, including:

S7-200 Series — all CPU variants
S7-300 Series — all CPU variants, including 314, 315 and 317 models
S7-400 Series — all CPU variants
S7-1200 Series — CPU 1211C, 1212C, 1214C, 1215C and 1217C variants
S7-1500 Series — all CPU variants, including F-series safety controllers

Threat actors are reportedly using AI assistance to generate scripts based on publicly available information about these PLCs. The scripts can be adapted for purposes including initial access, credential theft, denial-of-service attacks and other malicious objectives.

The agencies warned that internet-exposed or insufficiently segmented PLCs may be vulnerable to exploitation of known security flaws.

AI Lowers the Barrier for ICS Attacks

One notable aspect of the activity is the use of AI to accelerate the development and modification of attack tooling.

Among the tools observed is a custom Python script that incorporates open-source industrial automation libraries such as snap7.dll and python-snap7. The tooling can resemble legitimate monitoring software while interacting with PLC memory, configuration information and ladder logic through the S7comm protocol.

The agencies said AI-assisted development represents an evolution in offensive cyber capabilities because it can reduce the technical expertise, development time and resources traditionally required to create tools targeting industrial control systems.

“The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations,” the agencies warned.

Agencies Urge Stronger PLC Security

The U.S. agencies are urging owners and operators of Siemens S7 devices and other PLCs to strengthen their OT security controls.

Recommended measures include keeping PLCs and related software updated, preventing direct internet exposure wherever possible, implementing strong access controls, properly segmenting industrial networks and deploying security monitoring capable of detecting suspicious activity within ICS environments.

Organizations should also review externally accessible industrial devices and identify systems that may be running outdated software or relying on weak authentication and network controls.

AI-Powered Attack Also Targeted Asian Government Systems

The warning comes as cyber threat actors increasingly experiment with AI to automate different stages of attacks.

A recent report from Israeli cybersecurity company Dream detailed a highly automated campaign targeting government infrastructure in Asia. Although the original research did not identify the targeted government, reports from the Financial Times and Reuters identified Taiwan as the apparent target.

Taiwan’s Ministry of Digital Affairs said the attacks appeared to originate overseas and involved a hybrid approach combining conventional cyber operations with AI agents, including OpenClaw.

The activity took place between July 1 and July 4, 2026, across 12 attack waves. Researchers attributed the campaign to a likely Chinese-language operator and said it used an AI-powered framework built around the Hermes and OpenClaw agents.

The framework reportedly deployed multiple sub-agents simultaneously, allowing the attackers to automate reconnaissance, credential attacks, vulnerability research, API testing and data theft.

Multi-Agent Framework Automated Multiple Attack Stages

According to Dream, the operation divided tasks among several specialized AI agents:

A — SSO exploitation and credential attacks
B — JWT bypass testing and CAPTCHA attacks
C — Reconnaissance across government portals
D — API scanning and administrative panel bypass attempts
E — CVE research and vulnerability-chain testing
F — Supply-chain target assessment
I — Password spraying and CAPTCHA bypass
Q — Deep API endpoint exploitation

The framework reportedly discovered hidden API endpoints capable of returning authenticated sessions regardless of the request body. Attackers then used the information to collect employee usernames and conduct password-spraying attacks against government portals.

Researchers said the campaign ultimately resulted in the compromise of 85 accounts, along with the exfiltration of more than 2,564 personnel records, a database containing government system users, seven SSO client secrets, six internal database credentials and internal network IP ranges.

The operation also expanded beyond its initial targets. According to Dream, the attackers assessed government IT suppliers, a nuclear safety agency, a government email system and more than seven energy-sector companies for exposed administrative interfaces, misconfigurations and exploitable vulnerabilities.

AI Is Changing the Economics of Cyberattacks

The attack framework reportedly included a learning component capable of searching vulnerability databases, GitHub repositories and security research to identify techniques that could potentially be adapted to targeted infrastructure.

Dream said that over roughly four days, the operation generated 1,395 files, compromised 85 credentials, exfiltrated thousands of personnel records and established persistent access to government infrastructure.

The two campaigns highlight a growing concern for defenders: AI can increasingly automate activities that previously required significant time and specialized expertise.

For critical infrastructure operators in particular, the combination of internet-exposed industrial systems, known vulnerabilities, publicly available attack libraries and AI-assisted development could significantly increase the risk of attacks against inadequately protected OT environments.

As AI-enabled offensive capabilities continue to evolve, organizations operating PLCs and other industrial control systems will need to place greater emphasis on network isolation, asset visibility, timely patching, strong authentication and continuous OT security monitoring.

Leave a Reply

Your email address will not be published. Required fields are marked *