US authorities say Siemens controllers used for water and other infrastructure are being targeted by hackers — agencies claim threat actors use AI tools to generate exploitation scripts

3 hours ago 5

Various U.S. agencies just released a warning claiming that Iranian hackers are targeting Siemens S7-series programmable logic controllers (PLCs). According to the Cybersecurity and Infrastructure Security Agency (CISA) advisory, hackers are using publicly available information on these widely used devices to develop exploits that would enable remote access and control. They’re also using AI tools, allowing them to identify additional attack vectors and possibly adapt to any defensive measures operators may have taken to protect their systems.

“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the agency said in its warning. “The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk — it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.”

The warning comes from multiple government agencies, not just CISA. The advisory was also co-authored by the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE), and the Environmental Protection Agency (EPA), underscoring how serious this issue could become. Because of this, operators using Siemens S7 PLCs (and other PLCs operating critical infrastructure) are advised to keep their equipment updated with the latest applicable security patches, isolate it from the internet as much as possible, protect it with strong access controls, and deploy cybersecurity measures to monitor industrial control systems (ICS) for any anomalies and possible malicious activity.

What makes the threat especially dangerous is that the use of AI tools could enable potential attackers to make malicious files look and behave like legitimate monitoring tools. They achieve this by using open-source industrial automation libraries, making it easier for unsuspecting users to fall victim to their attacks. Although the agencies did not specify where these attacks could originate, they came less than a month after the water infrastructure of several states was hit by cyberattacks thought to have originated from Iran.

The proliferation of internet-connected devices in critical infrastructure has made them prime targets for both hackers seeking to make big money and nation-states seeking to gain an advantage over their opponents. This was made apparent in recent years when key government websites and online services in Ukraine went down just as the Russian military started pouring across its borders back in 2022. More recently, a worm from an unknown source wiped Iranian machines during the first quarter of 2026, which happened around the same time as the United States’ bombing campaign against the country.

There were even claims from Iran that networking devices from American and European companies failed during an attack even though they were disconnected from the rest of the world. Aside from these scenarios in active warfare, cyberattacks could also be used in gray warfare, where opponents can inflict maximum damage while retaining plausible deniability, reducing the chances of retaliation.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

Jowi Morales is a tech enthusiast with years of experience working in the industry. He’s been writing with several tech publications since 2021, where he’s been interested in tech hardware and consumer electronics.

Read Entire Article