Warning Issued from US Government: AI-Assisted Hackers Are Targeting Water Systems

Officials urged facilities to locate all controllers on their networks, install security updates, eliminate direct internet exposure, strengthen access controls, and monitor for suspicious activity.
Published: 8/21/2026, 4:54:51 PM EDT
Warning Issued from US Government: AI-Assisted Hackers Are Targeting Water Systems
Water pumped up from an underground well flows into a cistern on a farm in Fresno, Calif., on July 24, 2021. (Robyn Beck/AFP via Getty Images)
The United States government warned this week that hackers are using artificial intelligence-generated tools to target industrial controllers used in U.S. water systems, power facilities, and manufacturing plants, raising the risk of operational disruptions, equipment damage, and safety emergencies, according to the Cybersecurity and Infrastructure Security Agency (CISA).

CISA issued the alert with the FBI, the National Security Agency, the Department of Energy, and the Environmental Protection Agency. The warning is focused on Siemens S7 Series programmable logic controllers, small industrial computers used to automate machinery and essential operations.

“This is not a theoretical risk—it is an active threat,” the agencies said in the Aug. 19 advisory.

According to CISA, hackers are scanning the internet for Siemens controllers that are running outdated software or lack adequate security protections. They are using AI-generated programs disguised as legitimate monitoring tools to study the equipment and develop ways to gain access.

The use of AI represents “an evolution in threat actor capabilities,” according to CISA, by “dramatically reducing the technical expertise and time required” to produce working programs capable of exploiting industrial systems.

The activity has primarily targeted critical manufacturing, energy, water and wastewater treatment, chemical processing, food and agriculture, and commercial facilities, according to the advisory. Siemens controllers are also used within the defense industry.

Hackers who gain access to poorly protected controllers could interrupt industrial processes, damage equipment, compromise sensitive information, or cause safety incidents, according to the NSA. An intrusion could also affect other systems connected to a compromised facility.

At water utilities, industrial controllers can operate pumps and help regulate water pressure. A separate FBI-EPA alert issued July 30 documented cyberattacks against utilities in at least seven states. Reported effects included “loss of pressure and flooding,” as well as reduced monitoring and control.

According to the FBI and EPA, a pressure loss can create a public health risk by allowing untreated groundwater to seep into water pipes.

Those incidents involved Rockwell Automation controllers, not the Siemens equipment addressed in Wednesday’s advisory.

In a separate advisory updated in July, CISA said Iranian-affiliated hackers had targeted internet-connected industrial controllers, including equipment manufactured by Rockwell Automation, Schneider Electric, and Siemens.

Officials urged facilities to locate all controllers on their networks, install security updates, eliminate direct internet exposure, strengthen access controls, and monitor for suspicious activity.

Siemens also urged operators of its industrial control systems to install the latest updates, disconnect equipment from inadequately secured networks, and replace default or weak passwords, according to a security bulletin from the company’s cybersecurity response team.