Critical Infrastructure Under Threat: Hackers Target Siemens S7 PLCs Using AI

20.8.2026 | Autor: Top privacy
6

The NSA, CISA, and FBI are warning of active attacks on Siemens S7 PLCs in critical infrastructure. AI-generated exploits, vulnerable ports, and recommended measures.

Critical Infrastructure Under Threat: Hackers Target Siemens S7 PLCs Using AI

U.S. security agencies NSA, CISA, FBI, the Department of Energy (DoE), and the Environmental Protection Agency (EPA) issued a joint security advisory on August 19, 2026. In it, they warn that attackers are actively targeting Siemens S7 programmable logic controllers (PLCs) deployed across critical infrastructure in the U.S.

According to the agencies, this is not a theoretical risk, but an ongoing, active attack. Hackers are using AI-generated scripts, disguised as legitimate monitoring tools, to scan and manipulate devices accessible via the internet.

How Attackers Search for and Target Vulnerable Devices

Attackers use the internet search services Censys and ZoomEye to identify Siemens S7 PLCs that are publicly accessible via the internet or inadequately isolated from corporate networks. Once a vulnerable device is found, they use AI to quickly generate and fine-tune exploit code—significantly reducing both the time and technical expertise previously required to create a functional exploit for industrial control systems.

The tools utilize open-source automation libraries (specifically snap7.dll and python-snap7) to gain read and write access to the PLC’s memory, configuration data, and logic programs via the S7comm protocol—while masquerading as ordinary operational technology (OT) monitoring software to evade detection.

All major S7 product lines are at risk, including S7-200, S7-300, S7-400, S7-1200, and S7-1500, as well as the F-series safety controllers. Agencies warn that attackers are also exploiting devices left with default or minimally configured login credentials, which makes gaining initial access even easier.

Reconnaissance and Preparation for Future Attacks

Investigators view the current wave of activity more as ongoing reconnaissance and the development of attack capabilities than as immediate sabotage. The attackers appear to be testing techniques against specific PLC models and using read-only access to map the target environment—thereby effectively preparing for future write operations that could cause actual operational disruptions.

The sectors most at risk are critical manufacturing, energy, water and wastewater, the chemical industry, food and agriculture, and commercial facilities. The defense industry has also been identified as a potential target due to its use of Siemens controllers.

The timing of the advisory follows a series of recent cyber incidents at water treatment facilities in the states of Georgia, Minnesota, and Michigan, confirming that operational technology environments providing essential services remain a persistent target for attackers seeking to influence physical infrastructure.

The advisory lists potential consequences, including disruption of industrial processes and safety incidents caused by the manipulation of interlocking mechanisms or emergency shutdown systems, damage to equipment, prolonged outages, and cascading effects across interconnected supply chains.

Recommendations for Operators

The agencies urge all operators of Siemens S7 PLCs (and PLCs in general) to take immediate action in several areas:

  • conduct a complete inventory of all S7 devices on the network,
  • install the latest firmware and security patches, especially for controllers in the DMZ or accessible from external networks,
  • block TCP port 102 on perimeter firewalls and verify that no PLC is directly accessible from the Internet,
  • restrict access to the engineering tools TIA Portal and STEP 7 to authorized workstations only,
  • implement continuous monitoring, including ICS-specific intrusion detection, monitoring for anomalous S7comm communication, unauthorized write operations, and processes importing the snap7.dll library.

Organizations working with external integrators or managed service providers should share this advisory directly with them, as remote access can create blind spots that the system owner may not even be aware of.


OUR SERVICES
Source: Cyber Security News


Top privacy

Top privacy

“High-quality content isn’t created by copywriters, but by experts.”