The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency have issued a joint cybersecurity advisory warning of an active campaign targeting Siemens S7 Series programmable logic controllers used across U.S. critical infrastructure.
Released on August 19, the advisory describes a live and ongoing threat rather than a theoretical vulnerability.
Threat actors are reportedly using AI-generated exploitation scripts disguised as legitimate operational technology monitoring utilities to identify, access, and potentially manipulate Internet-exposed Siemens devices.
NSA and CISA Warn of Active Targeting of Siemens S7 PLCs
According to the agencies, attackers are leveraging Internet-wide scanning platforms, including Censys and ZoomEye, to identify Siemens S7 PLCs that are exposed directly to the public Internet or are inadequately segmented from enterprise environments.
After locating a target, adversaries can use AI-assisted development tools to generate, troubleshoot, and refine exploitation code faster than traditional manual development would allow.
This lowers the expertise threshold for industrial control system intrusion and enables attackers to tailor tooling to individual PLC models and exposed services.
The activity targets major Siemens S7 product families, including S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers, as well as F-series safety PLCs. These systems are widely deployed in manufacturing plants, energy facilities, water treatment environments, and other industrial operations.
The reported toolset relies on open-source automation components such as snap7.dll and python-snap7. These libraries communicate through the S7comm protocol and can provide access to PLC memory, configuration information, and ladder logic programs.
By presenting such utilities as routine monitoring or diagnostic software, threat actors may be able to blend malicious activity with normal engineering and maintenance workflows.
Read access alone can allow attackers to map industrial processes, identify control logic, and understand safety dependencies before attempting more disruptive actions.
The agencies also warned that exposed devices that use default credentials or are minimally configured for authentication remain especially vulnerable.
According to the agencies, weak access controls can provide attackers with an easier initial foothold, particularly when PLCs are accessible from corporate networks, vendor remote-access systems, or the public Internet.
Investigators assess the current activity as persistent reconnaissance and capability development. However, the same access could later enable unauthorized write operations, including changes to logic, setpoints, alarms, safety interlocks, or emergency shutdown processes.
Sectors identified as particularly exposed include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities, and the Defense Industrial Base.
The warning follows several recent cyber incidents affecting U.S. water utilities, highlighting the continued risk to operational technology environments that manage essential physical services.
A successful PLC compromise could disrupt industrial processes, damage equipment, trigger unsafe operating conditions, or cause prolonged downtime with supply-chain consequences.
The agencies urge organizations to immediately inventory all Siemens S7 devices and identify systems accessible from external networks or weakly segmented corporate environments.
Operators should apply available firmware updates and security patches, with particular attention to controllers positioned in demilitarized zones or remotely accessible network segments.
Organizations should block TCP port 102 at perimeter firewalls and ensure no PLC remains directly accessible from the public Internet. Access to TIA Portal and STEP 7 engineering environments should be restricted to approved workstations and authorized personnel only.
Continuous ICS-aware monitoring is also essential. Security teams should investigate anomalous S7comm traffic, unexpected PLC write operations, off-hours engineering connections, and Python processes importing snap7.dll on engineering workstations.
Asset owners should also review remote-access arrangements with integrators and managed service providers, as third-party connectivity can create exposure that internal teams may not recognize.
Organizations detecting suspicious activity should report it to CISA or the FBI’s Internet Crime Complaint Center. Entities subject to Department of Energy reporting obligations should continue following their established incident-notification procedures.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN