Five U.S. Agencies Say Attackers Are Using AI-Written Scripts Against Siemens Factory Controllers

Five U.S. federal agencies issued a joint advisory Aug. 19 saying that attackers are using scripts written with the help of AI to find and probe Siemens S7 programmable logic controllers, the small computers that run machinery in factories, power plants, and water systems.
The advisory, numbered AA26-231A, was released by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy, and the Environmental Protection Agency. "This is not a theoretical risk—it is an active threat," the agencies write. They name no country and no group, referring throughout to "threat actors."
The advisory says the targeted models are the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series. According to the agencies, the actors use commercial internet scanning services to locate controllers that are reachable from the internet and are running outdated software or are otherwise poorly protected, and the tools they then use are assembled from publicly available industrial automation code and made to look like legitimate monitoring software.
The sectors the agencies say are most targeted are critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. Siemens S7 controllers are also used in the defense industrial base, which the advisory says could be targeted as well.
The agencies assess that the pattern is "likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure." Also, the advisory reports no incident, no disruption, and no damage.
Their listed top mitigations are to inventory every S7 controller in an environment, apply security patches, make sure the devices cannot be reached from the internet, strengthen access controls, monitor for unauthorized activity, and hunt for anomalies. The advisory adds that the targeting is broader than Siemens equipment and that all owners of programmable logic controllers should apply the same measures.
Using AI to generate the scripts "dramatically" reduces the expertise and time an attacker needs to build working tools against industrial control systems, the agencies write.
