Free daily briefing on global business news.

The NSA, CISA, FBI, and other agencies say threat actors are using AI-generated scripts to target Siemens controllers across critical infrastructure sectors

Five federal agencies — the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency — jointly warned Wednesday that unknown hackers are actively probing Siemens S7 Series programmable logic controllers deployed throughout U.S. critical infrastructure and leveraging artificial intelligence to craft exploitation scripts that masquerade as legitimate monitoring tools.

Sectors identified as targets include critical manufacturing, energy, water and wastewater systems, chemical, food and agriculture, and commercial facilities, the agencies said. Siemens S7 Series PLCs — industrial computers that automate and control machinery and physical processes — are also used in the Defense Industrial Base, which the agencies said could be targeted as well.

The advisory states that hackers have been leveraging internet scanning services such as Censys and ZoomEye to identify Siemens PLCs that are exposed online and running outdated software or configured with weak authentication. They are then deploying AI-built Python scripts that leverage the snap7.dll library to obtain read and write access to PLC memory, configuration data, and ladder logic programs through the S7comm protocol. The tools are disguised as legitimate operational technology monitoring software to evade detection.