U.S. government agencies have issued a warning about hackers targeting critical infrastructure, specifically Siemens S7 Series programmable logic controllers (PLCs), using artificial intelligence in their attacks. These PLCs are integral to controlling processes in various sectors, including water, food, energy, chemicals, and manufacturing.
This alert marks the latest in a series of warnings regarding threats to critical infrastructure, particularly amid ongoing tensions with Iran, which has been implicated in previous cyber campaigns against U.S. water and wastewater systems. However, the current advisory does not explicitly attribute these attacks to any specific nation-state.
The National Security Agency (NSA), along with the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Energy Department, and the Environmental Protection Agency, described the attacks as an “active threat.” They warned that such intrusions could disrupt essential industrial processes, lead to safety incidents, or compromise sensitive data. The advisory highlights the use of AI-generated exploitation scripts, which significantly lower the technical barriers for attackers, allowing them to quickly adapt to defensive measures and exploit vulnerabilities.
Michael Garcia, a former CISA official, noted that this is the first time the agency has acknowledged the use of AI scripts in targeting operational technology systems in its cybersecurity advisories. Despite this advancement in attack methods, the advisory does not suggest using AI for defensive measures, instead recommending traditional security practices.
Experts from Frenos, an operational technology penetration testing company, expressed concern that the techniques used by attackers could extend beyond Siemens PLCs, indicating a broader risk to various industrial control systems. The advisory also mentioned that the AI-generated scripts are often disguised as legitimate monitoring tools, making detection more challenging.
For more details, refer to the full advisory published by the agencies involved here.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


