‘Not a theoretical risk,’ feds warn as attackers use AI-made code to hack critical infrastructure controllers
Five US federal agencies — the NSA, CISA, FBI, Department of Energy and Environmental Protection Agency — have issued a joint warning that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, energy, manufacturing and other critical infrastructure sites. Officials described the activity as "not a theoretical risk" but "an active threat", marking one of the first confirmed instances of AI tools being used operationally against industrial control systems rather than being a hypothetical concern raised by researchers.
The attackers combine open-source industrial automation libraries, specifically snap7.dll/python-snap7, with AI coding assistants to build custom tools that mimic legitimate operational technology monitoring software, granting read/write access to PLC memory, configuration data and ladder logic via the S7comm protocol. Although the alert does not formally attribute the campaign, security experts believe it is linked to Iranian cyber operatives already blamed for attacks on water and wastewater systems across at least 12 US states, including a disruption affecting more than 30 Minnesota community water systems in late July. Targets span critical manufacturing, energy, water, chemical, food and agriculture, and commercial sectors, with the Defense Industrial Base also flagged as potentially at risk; attackers reportedly locate vulnerable devices using internet-scanning tools such as Censys and ZoomEye.
- US feds warn AI-generated code is now hacking critical infrastructure PLCs
- Siemens S7 controllers targeted using open-source tools plus AI assistants
- Activity suspected linked to Iranian actors behind recent US water system attacks