mimile
Back to feed

NSA, FBI and CISA warn of AI-assisted attacks on Siemens S7 PLCs

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

NSA, FBI and CISA warn of AI-assisted attacks on Siemens S7 PLCs

Five U.S. agencies — the NSA, FBI, CISA, Department of Energy and Environmental Protection Agency — warned Aug. 19 that unspecified actors are mounting AI-assisted attacks on Siemens S7 Series programmable logic controllers at critical infrastructure facilities. The activity targets manufacturing, energy, water and wastewater, chemicals, food and agriculture, and commercial facilities. The warning comes as the government last month said Iran-backed actors are suspected of cyberattacks on municipal water systems.

Key Facts

  • The advisory was issued on Aug. 19 by the NSA, FBI, CISA, Department of Energy and Environmental Protection Agency.
  • The attackers are using AI-generated scripts disguised as legitimate monitoring tools and scanning services Censys and ZoomEye to find exposed Siemens S7 Series PLCs.
  • Targeted sectors include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities.
  • Exploitation of poorly protected PLCs could lead to disruption of industrial processes, safety incidents, downtime or equipment damage, data compromise and compliance violations.
  • The agencies did not attribute the activity to a known threat actor or group.

Joint Agency Advisory

The National Security Agency, FBI, Cybersecurity and Infrastructure Security Agency, Department of Energy and Environmental Protection Agency issued the advisory on Aug. 19. The advisory describes the PLC targeting as an active threat, not a theoretical risk. The ongoing PLC targeting activity is assessed to be broader in scope than Siemens PLCs. The agencies did not attribute the attacks to a known threat actor or group.

Attack Methods

The actors use AI-generated scripts disguised as legitimate monitoring tools to conduct reconnaissance and capability development against Siemens S7 Series PLCs. They leverage internet scanning services like Censys and ZoomEye to identify internet-exposed PLCs running outdated software or that are otherwise poorly protected. For a 900-employee water utility in the Midwest, John Watters, CEO of iCounter, said the utility has one IT person covering everything from email to PLCs running the treatment plant. Watters said the attackers' operation is low-cost and scalable, landing hardest on small utilities, small manufacturers and municipal systems that lack a dedicated OT security team. Gary Barlet, Public Sector CTO at Illumio, said expecting a small municipal utility or local water district to defend itself against automated AI-driven attacks is not a fair fight.

Sector Exposure

The six sectors listed as most at risk are Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. Exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data and compliance violations. The advisory also warns of cascading impacts across interconnected systems. Barlet said the federal government must play a more active role in helping communities build resilience, because patching cannot be the only answer to a real-time attack.

3 sources

NSA, FBI and CISA warn of AI-assisted attacks on Siemens S7 PLCs