Threat actors using AI to rapidly develop PLC exploitation scripts at unprecedented scale
NSA, CISA, FBI, DOE, and EPA have issued an urgent joint advisory warning of an active cyberattack campaign targeting Siemens S7 Series PLCs across U.S. critical infrastructure — with water and wastewater systems explicitly identified as among the most heavily targeted sectors.
Threat actors are using AI-generated exploitation scripts disguised as legitimate monitoring tools to conduct reconnaissance and read/write operations on internet-exposed or insufficiently segmented S7-200, S7-300, S7-400, S7-1200, and S7-1500 series controllers. The advisory characterizes AI-assisted script development as a significant evolution in threat actor capabilities, dramatically lowering the technical barrier to ICS attacks and enabling rapid adaptation to defensive measures. Actors are leveraging open-source industrial automation libraries — specifically snap7.dll and python-snap7 — combined with internet scanning services to identify vulnerable targets.
Potential impacts include disruption of critical processes, safety incidents, equipment damage, sensitive data compromise, and cascading effects across interconnected systems. The authoring agencies urge immediate action: conduct a full inventory of all Siemens S7 PLCs, apply current firmware patches, block TCP port 102 at perimeter firewalls, remove internet exposure, enable password protection and access controls, and deploy ICS-aware monitoring tools.
Rural water and wastewater operators using Siemens S7 controllers — particularly those relying on third-party integrators with remote PLC access — should treat this advisory as an immediate call to action and share it with all relevant service providers without delay.