
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA) have issued a joint Cybersecurity Advisory warning of threat activity targeting Siemens S7 Series programmable logic controllers (PLCs) across U.S. critical infrastructure.
The advisory, Defending Against an Active Threat to Siemens S7 Series PLCs, identifies the sectors most frequently targeted as critical manufacturing, energy utilities, water and wastewater systems and chemical plants. Successful attacks offer the potential to disrupt or shut down production processes, create safety incidents, damage equipment and/or compromise data. The cascading effects across communities and supply chains makes these threats especially concerning.
The advisory details cyber threat actors using AI-generated exploitation scripts disguised as legitimate monitoring tools, and leveraging internet scanning services to find exposed PLCs. Organizations using Siemens S7 Series PLCs are being urged to:
- Inventory devices.
- Apply critical patches.
- Ensure PLCs are not accessible from the internet.
- Strengthen access controls.
- Monitor for unauthorized activity.
- Harden PLC services and protocols.
- Hunt for anomalies that may indicate compromise.
- Assess exposure across all PLCs and operational technology (OT) devices in their environments.
Although this advisory focuses on Siemens S7 Series PLCs, the broader risk to OT devices, including PLCs, extends beyond Siemens products. But this should not be a new area of concern for manufacturers and industrial control system managers.
CISA and other government agencies have been sounding alarms over Iranian attacks on critical infrastructure, often originating from internet-connected devices and components. This goes back to a 2023 hack of Unitronics PLCs that started in Israel, but had a global impact. Similarly, the use of AI should come as no surprise, with hacker continuing to leverage this technology to increase attack scale and speed.
"Recent attacks on critical infrastructure have often centered on gaining persistent access, stealing sensitive information, or positioning inside networks for future operations," offers Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ.
"Campaigns tied to groups like Salt Typhoon have shown how valuable long-term access can be for espionage and surveillance, with the concern being that these intrusions can quietly create opportunities for more disruptive actions later.
"This latest exposure poses a bit of a different threat. The danger is more immediate because PLCs sit much closer to the physical processes that keep critical infrastructure running.
"Operators should assume these techniques will keep evolving. Patch management and segmentation are important first steps, but they can't be the finish line. Continuous adversarial emulation can expose weak points before attackers turn reconnaissance into real-world impact.”






















