The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency issued a joint advisory Wednesday warning of an active, ongoing threat targeting Siemens S7 Series programmable logic controllers (PLCs) in US critical infrastructure. The agencies say attackers are using AI-generated scripts disguised as legitimate operational technology (OT) monitoring tools to conduct reconnaissance and build attack capability.

According to the advisory, threat actors are relying on internet scanning services such as Censys and ZoomEye to locate exposed Siemens PLCs, then exploiting critical and high-severity vulnerabilities, outdated firmware, and weak authentication to gain access. The agencies note that AI is being used to develop custom Python exploitation scripts built on the ‘snap7.dll’ and ‘python-snap7’ libraries, which communicate with Siemens devices over the S7comm protocol. These tools can read and write PLC memory, configuration data, and ladder logic programs while masquerading as benign monitoring software.

Affected devices include the Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 product lines. The advisory stresses that while this specific campaign centers on Siemens hardware, broader PLC targeting activity extends beyond a single vendor, and all PLC owners and operators should apply relevant mitigations.

Sectors at risk

The agencies identify Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities as the most heavily targeted sectors. Because Siemens S7 PLCs are also used in the Defense Industrial Base, that sector could be exposed as well.

The current activity appears focused on persistent reconnaissance rather than immediate disruption, but officials warn it could be laying groundwork for more damaging follow-on actions, including data theft, equipment damage, extended downtime, or safety incidents.

Recommended mitigations

  • Inventory all Siemens S7 PLCs on the network
  • Apply the latest available security updates
  • Block direct internet access to PLCs
  • Strengthen authentication and access controls
  • Monitor for unusual read/write activity targeting PLC memory and configuration data

The advisory follows a string of recent attacks on exposed PLCs in US critical infrastructure, including a July incident that disrupted more than 30 Minnesota water utilities and forced some facilities into manual operation, and an April warning about Iranian-linked actors targeting internet-exposed Rockwell Automation and Allen-Bradley PLCs. CISA has separately warned of a broader rise in attacks against internet-facing PLCs used by water and wastewater utilities.