Hackers are actively targeting Siemens equipment used in water plants and other critical infrastructure, several U.S. agencies are warning.
The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), along with other agencies like the FBI, have issued a joint cybersecurity advisory this week detailing an active threat against Siemens S7 Series programmable logic controllers (PLCs).
These controllers are industrial computers used to operate physical equipment and processes, including pumps and valves at water treatment facilities.
“The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools,” the advisory reads.
According to the agencies, the attackers are using internet-scanning services to find Siemens PLCs that are exposed online and are running outdated software or are poorly protected. The sectors being targeted include manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. The agencies warn that a successful attack could disrupt critical industrial processes, create safety risks, damage equipment, cause downtime, or compromise sensitive operational data.
Additionally, AI seems to be playing a role.
The advisory says attackers are using AI to cut down on the technical expertise and time needed to develop exploits. Specifically, they are using AI-generated Python scripts to gain read and write access to Siemens PLCs while mimicking legitimate monitoring tools and avoiding detection.
The warning comes amid a recent wave of cyberattacks against U.S. water systems. In July, the FBI and EPA warned that hackers were targeting internet-connected PLCs at water and wastewater facilities. At the time, water systems in at least seven states reported incidents to the FBI. Months earlier, CISA and other federal agencies had issued a separate warning that Iranian-affiliated hackers were actively targeting PLCs used in critical infrastructure. Minnesota was hit particularly hard. State officials said roughly 36 municipal water systems were attacked.
President Donald Trump, however, downplayed the possibility that Iran was behind the Minnesota attacks and instead blamed the state and Gov. Tim Walz. “We heard in Minnesota there was a cyberattack and they blame it on Iran,” Trump said in a televised cabinet meeting. “I don’t think so. I blame it on Minnesota because they’re grossly incompetent.”
The latest Siemens advisory adds to mounting warnings from the federal government over the vulnerability of critical infrastructure in the United States. Siemens did not immediately respond to a request for comment.
The agencies recommend that operators take inventory of Siemens S7 Series PLCs, install critical security patches, make sure the controllers are not accessible from the internet, strengthen access controls, and monitor for suspicious activity.