<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc" -->

---
title: US agencies warn hackers are using AI-generated scripts...
description: Five US federal agencies (NSA, CISA, FBI, DOE, EPA) issued a joint advisory warning that threat actors are actively targeting Siemens S7 Series PLCs across...
canonical: https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: US agencies warn hackers are using AI-generated scripts to target Siemens PLCs | daily.dev
og:description: Five US federal agencies (NSA, CISA, FBI, DOE, EPA) issued a joint advisory warning that threat actors are actively targeting Siemens S7 Series PLCs across...
og:url: https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc
og:image: https://api.daily.dev/og/posts/sUFXChmhc.png
og:image:alt: US agencies warn hackers are using AI-generated scripts to target Siemens PLCs
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# US agencies warn hackers are using AI-generated scripts to target Siemens PLCs

**[Collections](https://daily.dev/sources/collections)** · 4 min read · 0 upvotes · 0 comments

## Summary

Five US federal agencies (NSA, CISA, FBI, DOE, EPA) issued a joint advisory warning that threat actors are actively targeting Siemens S7 Series PLCs across critical infrastructure sectors like energy, water, chemical, and defense. Attackers use scanning tools like Censys and ZoomEye to find exposed PLCs, then deploy Python scripts built with snap7.dll and python-snap7 libraries to communicate over the S7comm protocol, disguising the tools as legitimate OT monitoring software. Notably, officials say these scripts were built with AI coding assistants, lowering the technical bar for attackers. The advisory frames the activity as reconnaissance, with Iranian-affiliated actors suspected in related water system attacks across at least 12 states.

## Content

## What happened

In July, hackers targeted more than 100 internet-exposed water and wastewater systems across the US, and separately knocked a small UK power plant offline for four days. US agencies including CISA, the FBI, the NSA, the DOE, and the EPA have attributed the activity to Iran-affiliated actors. The UK government hasn't formally named anyone, but the timing and methods overlap closely enough that security officials on both sides of the Atlantic are treating these as part of the same campaign.

The US attacks hit facilities in at least a dozen states, including Minnesota, Michigan, Arkansas, Georgia, and New Jersey. Most were opportunistic rather than carefully planned - attackers scanned for exposed devices, found them, and went in. Some intrusions disabled shutdown processes and alarms on programmable logic controllers, creating potentially unsafe conditions without alerting operators. Water supply wasn't significantly disrupted, but the incidents caused outages during incident response and left some systems in states operators didn't know about.

The UK incident involved a peaker station - a small generator that runs during peak demand. It was offline for four days, which NCSC head Richard Horne described as the first successful attack of its kind on British energy infrastructure. The wider grid wasn't affected, and the site fell below the threshold for mandatory cyber incident reporting, which is part of why it didn't get more attention at the time.

## How the attacks worked

The technical method is worth understanding because it's a meaningful shift. Attackers used AI coding assistants to generate Python exploitation scripts built around the `snap7.dll` and `python-snap7` libraries, which communicate with Siemens S7 PLCs over the S7comm protocol. The scripts were designed to look like legitimate OT monitoring software while gaining read/write access to PLC memory, configuration, and ladder logic.

Targeted models included the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series - hardware that's common in water treatment, energy, manufacturing, chemical, and agricultural facilities. Attackers found exposed devices using internet scanning tools like Censys and ZoomEye. From there, the barrier to exploitation was low: many devices were running outdated firmware, using default credentials, or simply had no business being reachable from the public internet.

The AI angle matters here. Writing reliable industrial control system exploits used to require specialized knowledge of OT protocols and hardware behavior. AI coding tools compress that learning curve significantly. Officials described this as "not a theoretical risk" - the scripts were functional and deployed against real infrastructure.

## Who's most exposed

Rural water utilities are disproportionately affected. They often lack dedicated security staff, run older equipment, and haven't had the resources to audit what's internet-facing. The UK incident points to a different but related gap: smaller distributed energy assets frequently fall outside mandatory reporting thresholds, which means attacks on them can go unnoticed or unreported even when they succeed.

Security experts have flagged weak or default credentials on industrial controllers as a recurring problem across both incidents. The broader issue is that OT and IT networks are often insufficiently separated, and many operators are still relying on prevention as their primary strategy rather than building containment capabilities for when prevention fails.

## What agencies are recommending

The joint advisory from NSA, CISA, FBI, DOE, and EPA recommends:

- Inventory all PLCs and identify which are internet-accessible
- Remove internet exposure where possible; use VPNs or firewalls where it isn't
- Patch firmware and software, particularly on Siemens S7 series devices
- Replace default credentials and enforce strong authentication
- Monitor for anomalous S7comm traffic
- Strengthen OT/IT network separation

NCSC in the UK has separately warned that attacks on critical infrastructure could increase as tensions with Iran continue. The agency handled over 200 attacks on critical national infrastructure in the past year.

The core message from officials on both sides is straightforward: these systems shouldn't be reachable from the internet, and many of them still are.

## Questions this post answers

### How are attackers using AI to target Siemens S7 PLCs?

Attackers use AI coding assistants to help write Python scripts, built with the snap7.dll and python-snap7 libraries, that communicate with Siemens S7 PLCs over the S7comm protocol. These scripts are disguised as legitimate OT monitoring software, making them harder to detect, and can read and write PLC memory, configuration settings, and ladder logic once connected.

_Security teams tracking OT threats can follow evolving AI-assisted attack techniques on daily.dev._

### Which Siemens PLC models are affected by the S7comm-based attack campaign?

The campaign targets the entire S7 lineup, including S7-200, S7-300, S7-400, S7-1200, and S7-1500 models. Attackers first locate exposed devices using internet scanning tools like Censys and ZoomEye before deploying scripts to interact with them over the S7comm protocol.

_Infrastructure defenders monitoring PLC exposure risks can stay current on advisories via daily.dev._

### Who is suspected of being behind the attacks on Siemens PLCs and water systems?

Iranian-affiliated threat actors are suspected in related attacks on water systems across at least 12 US states, including one incident that disrupted operations in Minnesota. Five federal agencies, including the NSA, CISA, and FBI, frame the broader Siemens PLC targeting as reconnaissance likely preparing for future disruption, data theft, or physical equipment damage.

_Those tracking nation-state threats to critical infrastructure can follow developments on daily.dev._

## Similar posts on daily.dev

- [Siemens S7 PLC threat: What you need to know](https://daily.dev/posts/siemens-s7-plc-threat-what-you-need-to-know-xl3jbv20s) · Tenable Blog · 0 upvotes · 0 comments
- [Critical infrastructure’s long, undefended tail exposed by UK energy attack](https://daily.dev/posts/critical-infrastructure-s-long-undefended-tail-exposed-by-uk-energy-attack-hajfwhwyk) · CSO Online · 0 upvotes · 0 comments
- [Iran-linked cyberattack shut down a UK power plant](https://daily.dev/posts/iran-linked-cyberattack-shut-down-a-uk-power-plant-zukou3pe7) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ai-coding](https://daily.dev/tags/ai-coding)

[View this post on daily.dev](https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"US agencies warn hackers are using AI-generated scripts to target Siemens PLCs","url":"https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc"},"datePublished":"2026-08-20T00:28:42.281Z","dateModified":"2026-08-26T19:08:30.626Z","description":"Five US federal agencies (NSA, CISA, FBI, DOE, EPA) issued a joint advisory warning that threat actors are actively targeting Siemens S7 Series PLCs across...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7a838ccf7eb51745f05fa51b4e5c4e0f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7a838ccf7eb51745f05fa51b4e5c4e0f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ai-coding","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"US agencies warn hackers are using AI-generated scripts to target Siemens PLCs"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/us-agencies-warn-hackers-are-using-ai-generated-scripts-to-target-siemens-plcs-sufxchmhc#faq","mainEntity":[{"@type":"Question","name":"How are attackers using AI to target Siemens S7 PLCs?","acceptedAnswer":{"@type":"Answer","text":"Attackers use AI coding assistants to help write Python scripts, built with the snap7.dll and python-snap7 libraries, that communicate with Siemens S7 PLCs over the S7comm protocol. These scripts are disguised as legitimate OT monitoring software, making them harder to detect, and can read and write PLC memory, configuration settings, and ladder logic once connected. Security teams tracking OT threats can follow evolving AI-assisted attack techniques on daily.dev."}},{"@type":"Question","name":"Which Siemens PLC models are affected by the S7comm-based attack campaign?","acceptedAnswer":{"@type":"Answer","text":"The campaign targets the entire S7 lineup, including S7-200, S7-300, S7-400, S7-1200, and S7-1500 models. Attackers first locate exposed devices using internet scanning tools like Censys and ZoomEye before deploying scripts to interact with them over the S7comm protocol. Infrastructure defenders monitoring PLC exposure risks can stay current on advisories via daily.dev."}},{"@type":"Question","name":"Who is suspected of being behind the attacks on Siemens PLCs and water systems?","acceptedAnswer":{"@type":"Answer","text":"Iranian-affiliated threat actors are suspected in related attacks on water systems across at least 12 US states, including one incident that disrupted operations in Minnesota. Five federal agencies, including the NSA, CISA, and FBI, frame the broader Siemens PLC targeting as reconnaissance likely preparing for future disruption, data theft, or physical equipment damage. Those tracking nation-state threats to critical infrastructure can follow developments on daily.dev."}}]}
```

