AI-generated Scripts Used to Hack Siemens S7 PLCs

AI-assisted exploits target Siemens S7 PLCs in active critical infrastructure attacks

Attackers are now using AI-generated scripts to compromise Siemens S7 Series programmable logic controllers (PLCs), posing an immediate threat to critical infrastructure. The use of artificial intelligence to craft exploitation tools marks a significant escalation in tactics, affecting essential sectors from water treatment to manufacturing. This event highlights the urgent risks to internet-exposed Siemens S7 PLCs as AI accelerates the scale and sophistication of attacks.

AI-Generated Exploits Targeting Critical Infrastructure

On Wednesday, five major US federal agencies issued a joint advisory warning of active intrusions using AI-generated code targeting Siemens S7 PLCs. The attackers combine open source industrial automation libraries—primarily snap7.dll and python-snap7—with AI coding assistants to build custom tools. These tools mimic legitimate operational technology (OT) monitoring software and enable attackers to read and write to PLC memory, configuration data, and ladder logic programs using the S7comm protocol.

The advisory, released by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA), labels this as an “active threat” rather than a hypothetical risk. In the latest incidents, attackers leveraged AI-generated scripts for initial access, credential theft, denial of service, and direct manipulation of PLC logic, all of which can have severe consequences for critical services.

Detailed Attack Timeline and Techniques

Targeted Sectors and Devices

The attacks focus on Siemens S7 Series PLCs, which are widely deployed across:

  • Critical manufacturing
  • Energy
  • Water and wastewater systems
  • Chemical facilities
  • Food and agriculture
  • Commercial buildings

The advisory notes that Siemens S7 PLCs are also present in the Defence Industrial Base, increasing the range of potential impact. The campaign specifically targets devices that are directly exposed to the internet and often running outdated software or protected only by default credentials.

Attack Methods and Exploitation Tools

Attackers use internet-scanning services such as Censys and ZoomEye to identify vulnerable PLCs online. Once identified, they deploy AI-generated exploitation scripts tailored to the S7comm protocol. These scripts are capable of:

  • Modifying PLC memory and logic programs
  • Extracting configuration and credential data
  • Triggering denial-of-service conditions
  • Bypassing weak authentication mechanisms

The scripts are generated with the help of AI coding assistants, allowing attackers to rapidly adapt their tools to new targets or bypass specific security controls. The use of open source libraries such as snap7 makes it easier for threat actors to interact directly with Siemens PLCs, further lowering the barrier to entry for sophisticated attacks.

Timeline and Attribution

The campaign has been active throughout 2026, with US authorities noting a surge in incidents in late July. At least 12 states have reported attacks, including a significant cyberattack in Minnesota that disrupted operations at more than 30 community water systems. While the agencies have not officially attributed the campaign to any one group, Iranian cyber operatives are strongly suspected based on the tactics and targets observed.

The advisory marks the first public confirmation that AI technology is actively being used by state-affiliated adversaries to automate and scale attacks against operational technology in the US. Security experts interviewed in the wake of the advisory note that this trend is expected to accelerate, as AI assists threat actors in code generation, vulnerability discovery, and exploitation scripting.

Current Exploitation Status and Impact

According to the joint federal advisory, the threat is ongoing and evolving as attackers refine their AI-assisted techniques. The most recent wave of attacks has already caused significant disruption, particularly in the water sector, but the broad deployment of Siemens S7 PLCs means the threat extends to multiple critical industries. There is concern that similar techniques could be used to target PLCs in other sectors, potentially endangering essential services and public safety.

Authorities are urging immediate action, as attackers continue to scan for and exploit internet-exposed PLCs. The use of AI dramatically reduces the time required to develop new attack tools, allowing adversaries to scale their operations and quickly pivot to new targets.

Why This Threat Matters Now

This incident demonstrates a pivotal shift in the cyber threat landscape. The integration of AI into attack workflows allows adversaries to automate complex tasks, customise exploits, and respond to defences far more rapidly. For organisations relying on Siemens S7 PLCs, the risk is not theoretical: the attacks have already caused service disruptions, and the techniques are now easily replicable across sectors.

Immediate Steps for Organisations Using Siemens S7 PLCs

  • Remove direct internet exposure for all Siemens S7 PLCs and segment OT networks from IT and external access.
  • Enforce strong authentication and review all remote access configurations.
  • Monitor for any unusual S7comm protocol activity, which may indicate exploitation attempts.

Prompt remediation is essential to prevent further disruption as attackers continue to use AI-generated scripts to target critical infrastructure.

Originally reported by theregister.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call