Five U.S. agencies issued an urgent joint advisory on August 19, 2026, confirming for the first time in any government cybersecurity advisory that threat actors are using AI-generated code to attack Siemens S7 Series industrial controllers deployed at water treatment plants, power facilities, chemical plants, and manufacturing sites across the country — and that the same AI tools are making those attacks accessible to adversaries who could never have built them manually. Active threat to Siemens S7 PLCs “This is not a theoretical risk — it is an active threat,” the advisory states.

Advisory AA26-231A, co-signed by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy, and the Environmental Protection Agency, documents a specific attack technique: threat actors are using Censys and ZoomEye to scan the internet for Siemens S7 PLCs with port 102 exposed, then feeding that targeting data into AI tools that generate functional Python exploitation scripts using the open-source snap7 and python-snap7 libraries — the same libraries industrial engineers use to communicate legitimately with Siemens hardware. Those AI-written scripts are then disguised as legitimate operational technology monitoring software, giving attackers read and write access to PLC memory, configuration data, and ladder logic programs — the code that tells physical equipment what to do — without triggering malware detection.

Michael Garcia, a former senior CISA official now serving as vice president of the cybersecurity practice at Monument Policy Advocacy, called the advisory a milestone. “It is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems,” Garcia wrote on LinkedIn on August 19.

AI Collapsed the Expertise Barrier That Protected ICS from Casual Attackers

Attacking an industrial control system has historically required a specialized skill set that took years to develop: fluency in proprietary industrial protocols, knowledge of specific PLC architectures, the ability to write code that communicated natively with hardware designed for factory floors, not for the internet. That barrier protected Siemens controllers at water utilities, power stations, and chemical plants from all but the most sophisticated nation-state attackers.

AI code generation has now removed it.

The advisory describes the mechanism directly: “Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures.” An attacker who can describe the desired behavior in plain language — read the data blocks of a Siemens S7-1200, alter the ladder logic, disable the alarm routine — can now receive working code without understanding how the S7comm protocol is structured or how TPKT and COTP framing works at the network layer.

The open-source snap7 and python-snap7 libraries make this particularly dangerous. Snap7 is a freely available, multi-platform Ethernet communication suite that implements the full S7 protocol stack — including TPKT (RFC 1006), COTP (ISO 8073), and Siemens’ proprietary S7comm application layer — and is installable in seconds via pip. It was designed for legitimate industrial integration work. Paired with AI-generated scripting, it becomes a tool that can read and rewrite PLC programs on any internet-exposed Siemens controller that still runs the legacy S7comm protocol without authentication — which includes most S7-300 and S7-400 devices, and any S7-1200 or S7-1500 unit running firmware prior to version 4.0.

The advisory named a specific detection signal defenders can use: unauthorized use of snap7.dll outside approved systems. A water utility whose SCADA platform does not use snap7 that sees snap7 traffic on port 102 should treat it as an indicator of compromise.

Brian Proctor, CEO of Frenos, an OT penetration testing firm, highlighted a second risk: the exposure pattern is not limited to Siemens hardware. “Siemens S7 is the subject here, but the exposure pattern is not brand specific,” Proctor said in comments to CyberScoop’s coverage. “An adversary who has mapped your data blocks understands your process. They know what normal looks like, which means they know what an operator would fail to notice.”

Which Devices Are Targeted — and Why Older Ones Cannot Be Fixed with a Patch

The advisory covers Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 Series PLCs. These five product families represent the dominant installed base of Siemens industrial automation equipment in U.S. critical infrastructure — PLCs that regulate pumps, valves, conveyors, chemical dosing systems, and safety shutdown mechanisms at thousands of facilities.

The security vulnerability at the core of this attack is structural, not patchable with a software update. The original S7comm protocol — used by S7-300 and S7-400 devices, and by S7-1200 devices running older firmware — was designed with no authentication and no encryption, because it was intended for closed factory-floor networks, not for the internet. When such a device is reachable over the internet on port 102, any IP-level connection can initiate an S7comm session and issue read and write commands without credentials. There is no password to steal and no authentication mechanism to bypass.

Siemens addressed this in later hardware generations. S7-1200 devices running firmware version 4.0 or higher, and S7-1500 devices, use S7CommPlus, an updated protocol variant with encryption and replay protection. But S7-300 and older S7-400 units cannot be upgraded — the protocol implementation is embedded in hardware that does not support S7CommPlus. For those devices, the only meaningful mitigation is network isolation: removing internet connectivity entirely. The S7-1200 and S7-1500 vulnerability assessment published in Scientific Reports in April 2026 provides detailed technical context on the protocol differences and their security implications.

The sectors most frequently targeted by the advisory’s documented threat activity are critical manufacturing, energy utilities, water and wastewater systems, chemical plants, food and agriculture facilities, and commercial facilities. The advisory also notes that Siemens S7 PLCs serve defense contractors and could be targeted there as well.

What the Attack Chain Looks Like

Based on the advisory, a successful intrusion proceeds as follows. Threat actors use internet scanning services — Censys, ZoomEye, or similar — to enumerate Siemens S7 PLCs with port 102 (S7comm) exposed to the public internet. AI code generation then produces a Python script importing python-snap7 that connects to the target, reads data blocks to understand the industrial process being controlled, and can then write modified values or ladder logic back to the device. The script is packaged to resemble legitimate OT monitoring software — standard traffic that blends into network activity an operator would expect to see.

Once the attacker has write access, consequences can include: disruption of critical industrial processes; safety incidents by disabling alarm and shutdown routines; sustained equipment damage; extended downtime; exfiltration of PLC project files that reveal the full architecture of an industrial system; and, as confirmed in prior incidents, the manipulation of physical processes to create dangerous conditions that operators cannot detect on their dashboards.

A Week of Escalating Iran-Linked Enforcement

While advisory AA26-231A does not formally attribute the campaign to a specific nation-state, the broader context points clearly toward Iran. U.S. authorities have tracked an Iranian IRGC-affiliated group — formally known as the IRGC Cyber-Electronic Command (IRGC-CEC) and publicly designated as CyberAv3ngers — as the driver of industrial control system attacks against U.S. water, energy, and manufacturing facilities since at least November 2023. The group has been attributed to four escalating campaign phases, and its techniques have proliferated to an estimated 60 affiliated pro-Iranian hacktivist groups, according to Tenable Research cited in prior TechTimes coverage of this campaign.

One day before the Siemens advisory, on August 18, 2026, the Department of Justice unsealed a sweeping 14-count superseding indictment charging 17 members of the Mabna Institute — a Tehran-based company that federal prosecutors allege has conducted coordinated cyber intrusions for Iran’s Islamic Revolutionary Guard Corps since approximately 2013. The indictment, the largest expansion of the original 2018 Mabna case, adds eight newly identified defendants. Prosecutors allege the Mabna Institute penetrated 144 U.S. universities, 178 foreign universities, at least 42 U.S. private-sector companies, 11 foreign companies, five U.S. federal and state government agencies, and at least two nongovernmental organizations. The operation allegedly compromised roughly 8,000 professor email accounts worldwide and resulted in the theft of more than 31 terabytes of academic data and intellectual property. Prosecutors say the stolen research was sold through commercial websites inside Iran. The indictment also links several defendants to an attack on HBO systems, with an alleged attempt to extort the company for roughly $6 million in Bitcoin. The State Department’s Rewards for Justice program is offering up to $10 million for information leading to the location of several defendants.

The timing of the two actions underscores how Iran’s cyber operations have evolved into a dual-track campaign: intellectual property theft and academic espionage on one axis, and destructive or disruptive attacks on physical infrastructure on the other.

The ICS campaign targeting U.S. infrastructure escalated sharply following Operation Epic Fury — the U.S. and Israeli coordinated military strikes against Iran launched February 28, 2026. Cyberattacks against municipal water systems subsequently spread across at least 12 U.S. states, with federal investigators and U.S. intelligence officials attributing the campaign to Iran. In the most concentrated single incident, attackers struck more than 30 community water and wastewater systems across Minnesota on the nights of July 26 and July 27, temporarily shutting down one city’s water treatment plant and triggering a statewide emergency response involving the FBI, CISA, and the EPA. In at least one confirmed incident from that campaign, attackers disabled safety alarms and shutdowns, allowing unsafe operational conditions to develop without triggering alerts for facility staff.

CISA Acting Director Nick Andersen described the situation plainly in late July 2026: “CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,” according to reporting in prior TechTimes coverage.

What Operators Must Do Right Now

Advisory AA26-231A’s priority directive is straightforward: take internet-exposed Siemens S7 PLCs offline. Any facility whose S7 PLCs can be reached from the public internet on port 102 is, in the advisory’s language, at high risk for exploitation.

For facilities where some remote monitoring access is operationally necessary, the agencies specify that all external connectivity must route through VPNs with multi-factor authentication — not direct port forwarding, not cellular modem connections without controls. The advisory specifically calls out Dropbear SSH sessions on cellular modems attached to OT equipment as an attacker-controlled access vector that has already been exploited.

Additional required controls include: installing the latest available Siemens firmware updates; enabling hardware key switches on PLCs to prevent remote logic modification even if network access is achieved; auditing PLC project files for unauthorized changes to ladder logic; and monitoring for anomalous S7comm connections from non-engineering workstations or write operations outside scheduled change windows.

Organizations can download STIX-formatted indicators of compromise from CISA’s advisory page for deployment in SIEM, IDS, and firewall platforms. Suspicious activity can be reported to CISA’s 24/7 Operations Center or to local FBI field offices.

The regulatory gap that leaves water utilities structurally exposed — no federal mandatory cybersecurity baseline equivalent to the power grid’s NERC CIP standards — remains unresolved. Advisory AA26-231A does not change that gap. It documents, with increasing urgency, what it costs.

Frequently Asked QuestionsHow does AI change the threat to industrial control systems?

AI code generation collapses the specialized expertise barrier that previously limited ICS attacks to nation-state adversaries with trained engineers. Historically, attacking a Siemens PLC required deep knowledge of the S7comm protocol, PLC architecture, and industrial automation workflows — knowledge that took years to develop. AI tools can now generate functional Python scripts using the python-snap7 library that communicate directly with target PLCs over S7comm, without the attacker understanding the underlying protocol. The CISA advisory explicitly states that AI “dramatically reduc[es] the technical expertise and time required to develop working ICS exploitation scripts,” and former CISA official Michael Garcia confirmed this advisory is the first time the government has publicly stated in an operational technology cybersecurity advisory that malicious actors are using AI-generated scripts against OT systems.

Which Siemens PLCs are affected and can they be patched?

The advisory covers Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 Series PLCs. For S7-300 and S7-400 devices, and for S7-1200 devices running firmware below version 4.0, the vulnerability is structural — the legacy S7comm protocol has no authentication or encryption, and no firmware update can add those capabilities to those hardware generations. Siemens’ newer S7CommPlus protocol, with encryption and replay protection, is available on S7-1200 firmware 4.0 and higher and on S7-1500 devices, but it cannot be retrofitted to older units. For older PLCs, the only effective mitigation is network isolation — disconnecting them from any internet-accessible path.

Why are water utilities more exposed than other sectors?

Water utilities operate under no federal mandatory cybersecurity standards equivalent to what the power grid must meet under NERC CIP. The America’s Water Infrastructure Act of 2018 required water systems to develop risk assessments and emergency response plans, but the EPA found that 70% of inspected water systems were not in compliance even with that minimal requirement. The volunteer program that connects cybersecurity experts with small water utilities — DEF CON Franklin — had reached only 21 of an estimated 50,000 unprotected small utilities as of August 2026. The combination of outdated, internet-exposed PLCs, inadequate staffing, and no federal compliance floor makes water utilities the most systematically exposed sector in the current campaign.

What is the Mabna Institute and why was it indicted now?

The Mabna Institute is a Tehran-based company that federal prosecutors allege operated as a hacking-for-hire organization for Iran’s Islamic Revolutionary Guard Corps beginning around 2013. Its operators penetrated university research networks, stole academic data and intellectual property, and sold that material through commercial websites inside Iran. The original 2018 indictment charged nine members; the August 18, 2026 superseding indictment adds eight newly identified defendants, bringing the total to 17 across 14 counts. The DOJ press release details how the defendants are presumed innocent unless proven guilty. The timing — one day before the Siemens PLC advisory — illustrates the two tracks of Iran’s cyber campaign: intellectual property theft targeting universities and private-sector research, and disruptive attacks against physical infrastructure.