The U.S. National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy, and the Environmental Protection Agency warned of ongoing attacks targeting Siemens S7-series programmable logic controllers in U.S. critical infrastructure. In a joint advisory issued on August 19, 2026, the agencies reported that threat actors were using scripts developed with the help of artificial intelligence to exploit these industrial devices.
PLC units are industrial computers used to automate machinery and control physical processes inside factories and critical facilities. The sectors most targeted include critical manufacturing, energy, water and wastewater systems, chemicals, food and agriculture, and commercial facilities. The agencies also noted that Siemens S7 units are used in the defense industrial base, making it a potential target as well.
How Are the Attacks Carried Out?
Attackers search for exposed Siemens units using internet-scanning services, including Censys and ZoomEye, then attempt to exploit critical and high-severity vulnerabilities, outdated software, or weak authentication mechanisms. According to the advisory, the attackers developed Python-based exploitation tools that use the snap7.dll and python-snap7 libraries to communicate with Siemens S7 devices.
These tools disguise themselves as legitimate programs for monitoring operational technology (OT), but they can provide read and write access to controller memory, configuration data, and Ladder Logic programs through the S7comm protocol. The reported activity targets the S7-200, S7-300, S7-400, S7-1200, and S7-1500 models.
Why Does This Warning Matter?
The activity currently appears to focus on ongoing reconnaissance and information gathering, but it could pave the way for subsequent disruptive operations. The agencies said potential consequences include the theft of sensitive data, equipment damage, prolonged operational outages, or access leading to safety incidents. Because access to controller memory and programs can directly affect physical processes, protecting these devices is not limited to office network security.
The warning follows an increase in attacks on internet-exposed PLC units. In July, hackers targeted more than 30 water facilities in Minnesota, causing equipment malfunctions and prompting some facilities to temporarily switch to manual operation. CISA also warned of an increase in attacks on PLC units used by water and wastewater utilities. In April, U.S. agencies warned that Iran-linked hackers were targeting internet-exposed Rockwell Automation/Allen-Bradley units, with disruptions and financial losses recorded across multiple critical infrastructure sectors.
What Should Operators Do?
- Inventory Siemens S7 units within industrial environments and identify exposed devices.
- Install the latest available security updates.
- Block direct internet access to the units.
- Strengthen access controls and authentication.
- Monitor unusual activity targeting these devices or their protocols.
The agencies did not limit the warning to Siemens products alone, recommending that all owners and operators of PLC units implement appropriate mitigation measures to reduce risks to industrial devices and systems.