{"id":75511,"date":"2026-08-20T01:06:10","date_gmt":"2026-08-20T01:06:10","guid":{"rendered":"https:\/\/www.europesays.com\/germany\/75511\/"},"modified":"2026-08-20T01:06:10","modified_gmt":"2026-08-20T01:06:10","slug":"us-agencies-warn-of-active-cyber-threat-to-siemens-industrial-controllers-biggo-finance","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/germany\/75511\/","title":{"rendered":"US Agencies Warn of Active Cyber Threat to Siemens Industrial Controllers \u2014 BigGo Finance"},"content":{"rendered":"<p>Five US federal agencies issued a joint cybersecurity advisory on Wednesday warning that attackers are actively targeting Siemens S7 Series programmable logic controllers used across critical infrastructure sectors, including water treatment facilities, manufacturing plants, and energy systems. The alert, described by officials as addressing &#8220;an active threat&#8221; rather than a theoretical risk, comes in the wake of a wave of cyberattacks on municipal water systems across multiple states in recent weeks.<\/p>\n<p>The advisory was issued by the National Security Agency, the FBI, the Department of Energy, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency, which operates under the Department of Homeland Security. The agencies warned that the Siemens controllers, which serve as industrial computers managing physical processes such as pumps and valves at water treatment facilities, are being targeted across a broad range of sectors including manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities.<\/p>\n<p>The warning follows a series of incidents that cybersecurity experts have linked to Iranian operatives. In late July, more than 30 community water systems in Minnesota were disrupted by a cyberattack. State officials later put the figure at roughly 36 municipal water systems affected. The FBI and EPA had previously warned in July that hackers were targeting internet-connected PLCs at water and wastewater facilities, with water systems in at least seven states reporting incidents to the bureau.<\/p>\n<p>AI Lowers the Barrier to Entry<\/p>\n<p>A striking element of the latest advisory is the role of artificial intelligence. The agencies said attackers are using AI-generated exploitation scripts to gain read and write access to the Siemens devices, significantly reducing the technical expertise and time required to develop working exploits. The scripts are built using publicly available information about the S7 Series controllers and are disguised to mimic legitimate operational technology monitoring software.<\/p>\n<p>Specifically, the attackers are combining open source industrial automation libraries, notably snap7.dll and python-snap7, with AI coding assistants to create custom tools that provide access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol. The advisory notes that this approach represents &#8220;an evolution in threat actor capabilities,&#8221; allowing adversaries without deep OT expertise to rapidly develop functional industrial control system malware and attack chains.<\/p>\n<p>The hackers are also using internet-scanning services such as Censys and ZoomEye to locate exposed, poorly protected PLCs running outdated software or relying on default passwords. Once identified, these devices become targets for exploitation aimed at initial access, credential theft, denial of service, and other objectives.<\/p>\n<p>Cynthia Kaiser, senior vice president at the Halcyon Ransomware Research Center and a former FBI cyber division deputy assistant director, said the activity &#8220;appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs.&#8221; She added that &#8220;Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society.&#8221;<\/p>\n<p>Potential Consequences and Political Context<\/p>\n<p>The government advisory outlined a range of potential consequences if the devices are compromised, depending on specific circumstances. These include disruption of critical processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems. The agencies also noted that Siemens S7 Series PLCs are used in the Defense Industrial Base and could be targeted there as well.<\/p>\n<p>President Donald Trump has publicly downplayed the possibility of Iranian involvement in the Minnesota attacks. During a televised cabinet meeting, Trump said, &#8220;We heard in Minnesota there was a cyberattack and they blame it on Iran. I don&#8217;t think so. I blame it on Minnesota because they&#8217;re grossly incompetent.&#8221; The president made similar remarks on July 31, asserting he did not believe Iran was behind the water facility attacks while criticizing Minnesota officials, including Governor Tim Walz.<\/p>\n<p>Siemens did not immediately respond to a request for comment.<\/p>\n<p>Mitigation and Defense Recommendations<\/p>\n<p>The agencies recommended that critical infrastructure owners and operators take immediate action to inventory all Siemens S7 Series PLCs in their environments, apply security patches as needed, and ensure that no controllers are accessible from the internet. They also advised strengthening access controls and monitoring for suspicious activity.<\/p>\n<p>Specific detection strategies include watching for anomalous S7comm behavior, such as connections from non-engineering workstations, unusual data block access patterns, or write operations occurring outside approved change windows. Sequential IP scanning on port 102 and repeated connection attempts with varying parameters may indicate reconnaissance activity. The presence of Snap7.dll library usage outside approved workstations could also signal an intrusion.<\/p>\n<p>Benny Czarny, CEO and founder of critical infrastructure security firm Opswat, emphasized the importance of reducing the operational technology attack surface. &#8220;AI makes it much easier for an attacker to create and modify scripts targeting PLCs, so the barrier to attacking industrial systems continues to fall,&#8221; he said. &#8220;But for me the answer is not simply better AI detection.&#8221; Czarny recommended using data diodes where data only needs to flow out of an OT network, eliminating any network path back to the PLC for an attacker to exploit. &#8220;Stop giving attackers a path to the critical system in the first place,&#8221; he said.<\/p>\n<p>SectorExposureWater and wastewaterTargeted in recent attacks across at least 12 statesManufacturingIdentified in advisory as active targetEnergyIdentified in advisory as active targetChemicalIdentified in advisory as active targetFood and agricultureIdentified in advisory as active targetDefense Industrial BasePotential future target per advisory<\/p>\n<p>Note: Sectors listed in the joint federal advisory as facing active or potential threats to Siemens S7 Series PLC installations. The advisory did not specify which states beyond Minnesota were affected in the July incidents.<\/p>\n<p>The advisory represents the latest escalation in federal warnings about the vulnerability of US critical infrastructure. The convergence of internet-exposed industrial controllers, readily available open source tools, and AI-assisted exploit development has created conditions that security experts describe as increasingly difficult to defend against. For operators of water systems, manufacturing facilities, and other critical infrastructure, the message from Washington is unambiguous: the threat is not hypothetical, and the time to act is now.<\/p>\n","protected":false},"excerpt":{"rendered":"Five US federal agencies issued a joint cybersecurity advisory on Wednesday warning that attackers are actively targeting Siemens&hellip;\n","protected":false},"author":2,"featured_media":75512,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21002],"tags":[55713,6077,479,20244,3146,253,2067,6919,55716,55714,6487,55715],"class_list":["post-75511","post","type-post","status-publish","format-standard","has-post-thumbnail","category-siemens","tag-cybersecurity-and-infrastructure-security-agency","tag-department-of-energy","tag-donald-trump","tag-environmental-protection-agency","tag-fbi","tag-iran","tag-minnesota","tag-national-security-agency","tag-python-snap7","tag-s7-series-programmable-logic-controllers","tag-siemens","tag-snap7-dll"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/75511","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/comments?post=75511"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/75511\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media\/75512"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media?parent=75511"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/categories?post=75511"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/tags?post=75511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}