Feds warn attackers use AI-generated code to hack Siemens S7 PLCs

Feds warn attackers use AI-generated code to hack Siemens S7 PLCs

On Wednesday, 19 August 2026, five US federal agencies, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Department of Energy (DOE) and the Environmental Protection Agency (EPA), issued a joint security advisory warning that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs). The agencies called the danger "not a theoretical risk" but an active threat.

According to the advisory, attackers combine open source industrial automation libraries, specifically snap7.dll and python-snap7, with AI coding assistants to build custom tools that mimic operational technology (OT) monitoring software. Those tools give attackers read and write access to a PLC's memory, configuration data and ladder logic programs through the S7comm protocol. Attackers typically find exposed units first, using internet-scanning services such as Censys and ZoomEye to locate PLCs running outdated software or default passwords.

The affected Siemens S7 Series PLCs sit in critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, and the agencies note that Siemens S7 PLCs used in the Defense Industrial Base could be targeted too. The advisory states that threat actors are using AI assistance to generate exploitation scripts from publicly available information about these PLCs for initial access, credential access, denial of service and other objectives, and that where a PLC is exposed to the internet or insufficiently segmented, attackers can exploit known critical and high severity vulnerabilities in it. The agencies describe the use of AI here as an evolution in threat actor capabilities: it cuts the need for advanced OT knowledge and lets an attacker build working industrial control system malware and attack chains faster.

The joint alert does not attribute this AI-assisted activity to a specific government or criminal group. Separately, Iranian cyber operatives are suspected of running a different, ongoing campaign against water and wastewater PLCs across at least 12 US states, including a late-July attack that disrupted more than 30 community water systems in Minnesota; national security and infosec experts told The Register the week before this advisory that they saw no indication AI was used in those particular intrusions. Cynthia Kaiser, senior vice president at the Halcyon Ransomware Research Center and a former FBI cyber division deputy assistant director, told The Register the new AI-assisted activity "appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs," and that Iran-affiliated actors are targeting operational technology broadly because, in her words, "these PLCs underpin essential health, safety, and critical infrastructure across society." That link is her own assessment, not a finding stated in the advisory itself. Kaiser added that the advisory's picture of AI use matches what her team expected: state-sponsored actors leaning on AI for discrete tasks such as code checks and scripting to move faster and scale up.

Benny Czarny, CEO and founder of critical infrastructure security firm Opswat, told The Register that the bigger problem is still how exposed OT environments are. AI, he said, makes it much easier for an attacker to create and modify scripts targeting PLCs, so the barrier to attacking industrial systems keeps falling, but the answer is not simply better AI detection. His recommended fix is structural: use a data diode where data only needs to leave an OT network, make sure there is no network path back to the PLC, and do not rely on antivirus or sandboxes to protect that data flow.

The agencies' own mitigation advice is to immediately inventory every Siemens S7 Series PLC in the environment, apply security patches, and confirm no PLC is reachable from the internet. They also list indicators to watch for: connections to a PLC from non-engineering workstations, unusual data block access patterns, write operations outside scheduled change windows, sequential IP scanning on port 102, repeated connection attempts with varying parameters, and Snap7.dll library activity from workstations that are not approved to use it. The Register says it asked the five agencies for more detail about the attacks but had not received a response as of publication.

Key facts

  • Five US agencies, NSA, CISA, FBI, DOE and EPA, issued a joint advisory on Wednesday, 19 August 2026, calling AI-generated attacks on Siemens S7 Series PLCs "not a theoretical risk" but an active threat.
  • Attackers pair the open source snap7.dll/python-snap7 libraries with AI coding assistants to build tools that mimic OT monitoring software and gain read/write access to a PLC's memory, configuration data and ladder logic via the S7comm protocol.
  • Targeted sectors include critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, plus equipment used in the Defense Industrial Base.
  • The advisory does not attribute the AI-assisted intrusions to any government or group; a separate, apparently non-AI campaign that Iranian operatives are suspected of running hit water PLCs across at least 12 states, including a late-July attack that disrupted more than 30 community water systems in Minnesota.
  • Agencies tell operators to immediately inventory every Siemens S7 PLC, patch it and take it off the internet, and watch for indicators such as sequential IP scanning on port 102; Opswat's Benny Czarny argues the real fix is cutting network paths to PLCs, for example with a data diode, rather than relying on better AI detection.

Why it matters

The advisory documents a shift from a warned-about risk to what the agencies call an active threat: attackers no longer need deep operational-technology expertise to go after industrial control systems, because AI can generate and adjust the exploitation scripts for them from publicly available information about the Siemens S7 Series PLCs. The alert calls this "an evolution in threat actor capabilities." Because these controllers sit inside water, energy, manufacturing, chemical, food and commercial systems, and in Defense Industrial Base equipment, a lower technical bar for attacking them raises the stakes well beyond a typical IT security incident.

Who it affects

Directly affected are operators of internet-exposed Siemens S7 Series PLCs across critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, plus equipment used in the Defense Industrial Base. The advisory is addressed to those owners and operators, not to the public. What that exposure can mean for everyone else showed up in late July, when a separate incident, one the agencies do not link to this AI-assisted method, disrupted more than 30 community water systems in Minnesota.

How to use it

The agencies' immediate guidance is to inventory every Siemens S7 Series PLC in the environment, apply available security patches, and make sure none is reachable from the internet. Beyond that, they list indicators worth hunting for: connections to a PLC from non-engineering workstations, unusual data block access patterns, write operations outside scheduled change windows, sequential IP scanning on port 102, repeated connection attempts with varying parameters, and Snap7.dll activity from workstations not approved to use it. Opswat's Benny Czarny frames the fix differently: use a data diode where data only needs to leave an OT network, remove any network path back to the PLC, and do not depend on antivirus or sandboxing to protect that data flow.

How solid is it

The central claim rests on a named joint advisory from five federal agencies, NSA, CISA, FBI, DOE and EPA, about as authoritative a source as a security warning gets, and The Register adds on-record comments from two outside experts, Halcyon's Cynthia Kaiser and Opswat's Benny Czarny. What the article does not supply: which AI tool or model the attackers used, CVE identifiers for the "critical and high severity known vulnerabilities" the alert says are exploitable, the advisory's own document number, a timeline for how long the AI-assisted technique has been active, or a count of how many facilities or PLCs have actually been compromised; only the method and detection indicators are described. The Register says it asked the five agencies for more detail and got no response.

Risks and caveats

The biggest caveat is attribution. The joint alert does not name a government or group behind the AI-assisted intrusions. A different campaign, one that Iranian operatives are suspected of running against water and wastewater PLCs in at least 12 states, including the Minnesota disruption, is a separate matter that experts told The Register last week showed no sign of AI involvement. Kaiser's comment that the new activity "appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs" is her own assessment, not an attribution made in the advisory itself, and the two campaigns should not be read as confirmed to be the same one.

“Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives”

— the joint security advisory from NSA, CISA, FBI, DOE and EPA