Skip to content
See the World Through Science

Five U.S. Agencies Say Attackers Are Using AI-Written Scripts Against Siemens Factory Controllers

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A Siemens Simatic S7-1200 programmable logic controller mounted on a DIN rail with wiring terminals and status LEDs
A Siemens Simatic S7-1200 programmable logic controller, one of the S7 model families named in the joint advisory."Simatic S7-1200" by UlrichAAB, via wikimedia, CC-BY-SA-3.0 · CC-BY-SA-3.0

Five U.S. federal agencies issued a joint advisory Aug. 19 saying that attackers are using scripts written with the help of AI to find and probe Siemens S7 programmable logic controllers, the small computers that run machinery in factories, power plants, and water systems.

The advisory, numbered AA26-231A, was released by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy, and the Environmental Protection Agency. "This is not a theoretical risk—it is an active threat," the agencies write. They name no country and no group, referring throughout to "threat actors."

The advisory says the targeted models are the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series. According to the agencies, the actors use commercial internet scanning services to locate controllers that are reachable from the internet and are running outdated software or are otherwise poorly protected, and the tools they then use are assembled from publicly available industrial automation code and made to look like legitimate monitoring software.

The sectors the agencies say are most targeted are critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. Siemens S7 controllers are also used in the defense industrial base, which the advisory says could be targeted as well.

The agencies assess that the pattern is "likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure." Also, the advisory reports no incident, no disruption, and no damage.

Their listed top mitigations are to inventory every S7 controller in an environment, apply security patches, make sure the devices cannot be reached from the internet, strengthen access controls, monitor for unauthorized activity, and hunt for anomalies. The advisory adds that the targeting is broader than Siemens equipment and that all owners of programmable logic controllers should apply the same measures.

Using AI to generate the scripts "dramatically" reduces the expertise and time an attacker needs to build working tools against industrial control systems, the agencies write.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Five U.S. Agencies Say Attackers Are Using AI-Written Scripts Against Siemens Factory Controllers

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.