
Five U.S. agencies — NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency — issued a joint advisory Wednesday warning that threat actors are using AI-generated scripts to actively attack Siemens S7 Series programmable logic controllers (PLCs) across U.S. critical infrastructure. The advisory is notable for its explicit focus on artificial intelligence as an attack-enablement tool: attackers use internet-scanning platforms like Censys and ZoomEye to locate exposed devices, then deploy AI-generated Python scripts that exploit the snap7.dll and python-snap7 libraries to communicate directly with PLCs over the S7comm protocol. These tools are disguised as legitimate operational technology (OT) monitoring software but can read and write to PLC memory, configuration data, and ladder logic — the programming that controls physical processes.
The advisory covers Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs. Targeted sectors include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities, and the Defense Industrial Base. The agencies assess current activity is focused on reconnaissance and positioning, potentially as a precursor to equipment damage, extended downtime, data theft, or safety incidents. This advisory follows a July incident where hackers hit more than 30 Minnesota water utilities using similar PLC-targeting techniques.
How to check if you’re affected
Affected products include Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 Series PLCs used in industrial or utility environments. Operators should inventory exposed devices, apply the latest firmware updates, block direct internet access to PLCs, strengthen access controls, and monitor for unusual S7comm protocol traffic.
