US cybersecurity agencies have warned that ongoing Siemens S7 PLC attacks are targeting critical infrastructure organisations with AI-generated exploitation scripts.
The joint alert comes from the NSA, CISA, FBI, Department of Energy and Environmental Protection Agency. It warns that attackers are actively seeking exposed Siemens S7 Series programmable logic controllers, or PLCs, across the United States.
PLCs automate physical processes and machinery. They play a central role in factories, power systems, water facilities and other operational technology environments. As a result, a successful intrusion could create risks beyond data theft.
Siemens S7 PLC attacks target exposed systems
The agencies said the activity affects several Siemens device families, including the S7-200, S7-300, S7-400, S7-1200 and S7-1500.
Threat actors reportedly use internet scanning platforms to identify devices that operators have exposed online. They then look for critical or high-severity flaws, outdated software and weak authentication settings.
The warning focuses on critical manufacturing, energy, water and wastewater systems, chemical facilities, food and agriculture, and commercial facilities. Siemens S7 PLCs also operate within the defence industrial base.
However, the agencies stressed that the wider threat extends beyond Siemens equipment. PLC owners and operators should apply appropriate protections regardless of their device manufacturer.
AI-generated scripts can access PLC data and logic
According to the advisory, attackers are using artificial intelligence to produce Python scripts designed to communicate with Siemens S7 devices.
The tools use the snap7.dll and python-snap7 libraries, which support communication through the S7comm protocol. Attackers disguise the scripts as legitimate operational technology monitoring software.
Once deployed, the tools can reportedly read and write PLC memory, access configuration data and interact with ladder logic programs. Ladder logic controls how industrial equipment performs automated tasks.
The agencies believe the activity currently centres on persistent reconnaissance. Yet that access could allow attackers to prepare for more serious disruption later.
Potential consequences include stolen sensitive information, damaged equipment, prolonged downtime and safety incidents.
Agencies urge operators to tighten defences
Organisations should first identify every Siemens S7 PLC in their environment and confirm which systems connect to the internet.
The advisory also urges operators to install current security updates and block direct internet access to PLCs wherever possible. Stronger authentication and tighter access controls can further reduce the risk of compromise.
In addition, security teams should monitor for unusual activity involving industrial devices and investigate unexpected connections quickly.
The warning follows several recent attacks against internet-exposed PLCs. In July, attackers reportedly targeted more than 30 water utilities in Minnesota, causing equipment problems and forcing some facilities to temporarily switch to manual operations.
Earlier warnings also highlighted attacks against exposed Rockwell Automation and Allen-Bradley PLCs. The latest alert shows that Siemens S7 PLC attacks remain an active concern for critical infrastructure operators.


0 responses to “Siemens S7 PLC Attacks Use AI Scripts, US Agencies Warn”