started · updated
U.S. agencies warn of AI-assisted attacks on Siemens S7 PLCs
Five U.S. federal agencies, including the NSA, CISA, FBI, Department of Energy, and EPA, have issued a joint advisory warning of active, AI-assisted hacking campaigns targeting Siemens S7 Series programmable logic controllers (PLCs). The threat affects multiple generations of hardware, ranging from the S7-200 to the S7-1500 F-series safety controllers.
The attackers are utilizing AI-generated Python scripts to exploit known vulnerabilities, a method that reduces the technical expertise required to carry out such attacks. These scripts are designed to mimic legitimate operational technology (OT) monitoring tools, making them difficult for security teams to detect. The actors leverage open-source libraries, such as snap7.dll and python-snap7, to communicate via the S7comm protocol on TCP port 102, granting them access to PLC memory, configuration data, and ladder logic programs.
Targeted sectors include critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. The advisory notes that attackers use internet scanning services to identify exposed PLCs running outdated or poorly protected software. Recent incidents include an attack on over 30 water treatment plants in Minnesota in late July, which forced one facility to switch to manual operations.
Entities
CISA · Department of Energy · FBI · NSA · Siemens