US Agencies Warn of AI-Built Exploits Hitting Siemens PLCs
Five US agencies report active attacks on Siemens S7 controllers in critical infrastructure — driven by exploit scripts generated with AI.

Illustration · AI-generated (AI IN LIFE)
At a glance
- Advisory AA26-231A by NSA, CISA, FBI, Department of Energy and EPA (20 August 2026)
- Affected lines: Siemens S7-200, S7-300, S7-400, S7-1200, S7-1500
- Method: AI-generated exploit scripts built on snap7/python-snap7
- Targets located via internet scanners such as Censys and ZoomEye
- Sectors: energy, water/wastewater, chemicals, manufacturing, food
What happened? Five US agencies — the NSA, CISA, the FBI, the Department of Energy and the EPA — warn in a joint advisory (AA26-231A) of active attacks on Siemens S7-series industrial controllers. According to the advisory, the affected lines are the S7-200, S7-300, S7-400, S7-1200 and S7-1500, which control valves, pumps and machinery in industrial plants worldwide.
What role does AI play? Attackers combine open-source libraries such as snap7 and python-snap7 with AI-generated scripts. The agencies write that using AI to generate exploitation scripts "represents an evolution in threat actor capabilities" and dramatically reduces "the technical expertise and time required to develop working ICS exploitation scripts".
How do the attacks work? According to the agencies, the actors use internet scanners such as Censys and ZoomEye to find exposed S7 devices, then gain access via default or weak credentials and the S7comm protocol. Affected sectors include energy, water and wastewater, chemicals, critical manufacturing, and food and agriculture.
How serious is it? "This is not a theoretical risk — it is an active threat," the advisory states. CNBC reports that the warning follows recent breaches of US water utilities, with investigators also looking at Iranian actors.
What should operators do now? The agencies recommend inventorying all S7 devices, applying patches, strictly isolating controllers from the internet, hardening access controls and actively checking systems for compromise. For European industrial firms, the advisory is a clear prompt to review exposed legacy controllers without delay.
FAQ
Which devices does the warning cover?
Siemens S7-series controllers: S7-200, S7-300, S7-400, S7-1200 and S7-1500, where they are reachable from the internet.
What is new about these attacks?
Attackers have AI generate the exploit scripts — which, per US agencies, sharply lowers the effort and expertise required.
What do the agencies recommend?
Inventory all S7 devices, patch, isolate them from the internet, harden access controls and run compromise assessments.


