Federal agencies warn AI-assisted hacking tools are lowering barriers to attacks on industrial control systems used across critical infrastructure.

Federal cyber agencies are warning critical infrastructure owners and operators of an active threat targeting Siemens S7 Series programmable logic controllers (PLCs). Attackers are using artificial intelligence (AI) to develop tools to exploit poorly protected controllers, the agencies said.

The Cybersecurity and Infrastructure Security Agency (CISA), FBI, National Security Agency (NSA), Energy Department, and Environmental Protection Agency issued the warning in an Aug. 19 cybersecurity advisory.

“This is not a theoretical risk – it is an active threat,” the agencies said. “Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.”

The threat is most heavily targeting critical infrastructure sectors including critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, according to the advisory.

The agencies said Siemens S7 Series PLCs are also used in the defense industrial base and could be targeted there as well.

Threat actors are using internet scanning services, such as Censys and ZoomEye, to identify internet-exposed or insufficiently segmented Siemens PLCs. They are also using AI tools to generate exploitation scripts for initial access, credential access, denial of service, and other objectives.

The agencies said AI-assisted development lowers the technical barriers and time needed to develop working industrial control system (ICS) exploitation tools.

Attackers are also combining AI-generated scripts with open source industrial automation libraries – specifically snap7.dll and python-snap7 – to create tools that mimic legitimate operational technology monitoring software.

“The authoring agencies assess this activity pattern is likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure,” the advisory says.

To reduce the risk, the agencies are urging owners and operators to immediately inventory Siemens S7 Series PLCs, apply critical security patches, prevent PLCs from being accessible from the internet, strengthen access controls, and monitor for unauthorized activity.

However, the agencies cautioned that ongoing PLC targeting extends beyond Siemens devices and urged all PLC owners and operators to apply relevant mitigations.

Read More About