CISA issued the alert with the FBI, the National Security Agency, the Department of Energy, and the Environmental Protection Agency. The warning is focused on Siemens S7 Series programmable logic controllers, small industrial computers used to automate machinery and essential operations.
“This is not a theoretical risk—it is an active threat,” the agencies said in the Aug. 19 advisory.
According to CISA, hackers are scanning the internet for Siemens controllers that are running outdated software or lack adequate security protections. They are using AI-generated programs disguised as legitimate monitoring tools to study the equipment and develop ways to gain access.
The use of AI represents “an evolution in threat actor capabilities,” according to CISA, by “dramatically reducing the technical expertise and time required” to produce working programs capable of exploiting industrial systems.
The activity has primarily targeted critical manufacturing, energy, water and wastewater treatment, chemical processing, food and agriculture, and commercial facilities, according to the advisory. Siemens controllers are also used within the defense industry.
Hackers who gain access to poorly protected controllers could interrupt industrial processes, damage equipment, compromise sensitive information, or cause safety incidents, according to the NSA. An intrusion could also affect other systems connected to a compromised facility.
According to the FBI and EPA, a pressure loss can create a public health risk by allowing untreated groundwater to seep into water pipes.
Those incidents involved Rockwell Automation controllers, not the Siemens equipment addressed in Wednesday’s advisory.
Officials urged facilities to locate all controllers on their networks, install security updates, eliminate direct internet exposure, strengthen access controls, and monitor for suspicious activity.
