CISA, NSA and FBI Warn of Active AI-Assisted Reconnaissance Against Siemens S7 PLCs

Industrial process room monitored for combustible and toxic gases

Joint Advisory Warns of Active Targeting

The National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency released a joint cybersecurity advisory on August 19, 2026, warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The advisory, designated AA26-231A, covers the S7-200, S7-300, S7-400, S7-1200 and S7-1500 controller families, including the F-series safety variants.

According to the agencies, the activity spans several critical infrastructure sectors, with Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities named as the most-targeted. Siemens S7 controllers are also used in the Defense Industrial Base, which the advisory says could be affected as well. CISA describes the threat as “not a theoretical risk” and says exploitation of poorly protected PLCs could disrupt industrial processes, damage equipment, trigger safety incidents through manipulation of interlocks or emergency shutdown systems, and cause cascading effects across interconnected systems.

AI-Generated Scripts and the Snap7 Library

The advisory says the threat actors are combining publicly available industrial automation tooling with AI-assisted scripting to build custom software that mimics legitimate operational-technology monitoring tools. Specifically, the agencies describe adversaries using internet-scanning services such as Censys and ZoomEye to locate exposed S7 controllers, then deploying AI-generated Python scripts built on the open-source snap7 library to read and write PLC memory, configuration data and ladder-logic programs over the S7comm protocol on TCP port 102. CISA characterizes the use of AI to generate this exploitation code as “an evolution in threat actor capabilities” that lowers the technical bar for building working industrial-control exploitation tools and speeds adversaries’ ability to adapt to defenses.

The agencies assess the pattern observed so far as consistent with reconnaissance and capability development — testing techniques against specific PLC models and using read access to understand target environments — rather than a confirmed disruptive attack. The advisory maps the observed techniques to the MITRE ATT&CK for ICS and Enterprise frameworks and to MITRE D3FEND countermeasures.

A Distinct Threat From the Iran-Linked Water Sector Warning

AA26-231A is separate from an earlier joint advisory, AA26-097A, which described confirmed Iran-linked exploitation of PLCs at a U.S. water-sector victim, including modification of ladder logic that disabled safety shutdown and alarm functions. The new Siemens-specific advisory does not attribute the reconnaissance activity it describes to any named nation-state or group, and it explicitly frames the observed activity as pre-attack staging rather than a confirmed disruptive incident. CISA also cautions that PLC targeting more broadly extends beyond Siemens equipment, and that the Siemens-specific guidance in the advisory should be treated as one subset of a wider threat landscape facing internet-exposed industrial controllers.

Mitigations Recommended by the Authoring Agencies

The agencies are urging asset owners to inventory all Siemens S7 controllers in their environments, apply available firmware and engineering-software patches, verify that PLCs are not reachable from the internet, and block TCP port 102 at perimeter firewalls. Additional recommendations include restricting engineering-workstation access through IP or MAC allowlisting, enabling PLC password protection and configurable read/write protection levels, deploying ICS-aware intrusion detection, and monitoring for anomalous S7comm traffic patterns, unauthorized write operations, and use of the snap7 library outside approved engineering systems. The advisory also recommends organizations that rely on third-party systems integrators or managed service providers share the guidance with those parties directly, since asset owners may not always be aware that PLCs accessible to vendors are also exposed to the wider internet.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *