{"id":76362,"date":"2026-08-21T07:39:08","date_gmt":"2026-08-21T07:39:08","guid":{"rendered":"https:\/\/www.europesays.com\/germany\/76362\/"},"modified":"2026-08-21T07:39:08","modified_gmt":"2026-08-21T07:39:08","slug":"siemens-says-no-spike-in-attacks-despite-us-warning-on-hacked-industrial-controllers-biggo-finance","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/germany\/76362\/","title":{"rendered":"Siemens Says No Spike in Attacks Despite US Warning on Hacked Industrial Controllers \u2014 BigGo Finance"},"content":{"rendered":"<p>Siemens said Wednesday it has not detected an increase in cyberattacks or any previously unknown vulnerabilities in its industrial control equipment, pushing back against a sweeping US government advisory that warned hackers are actively targeting the company&#8217;s S7 Series programmable logic controllers used across critical infrastructure.<\/p>\n<p>The German industrial giant said it is in close contact with the Cybersecurity and Infrastructure Security Agency, adding that the joint advisory issued Tuesday by multiple US agencies points to hackers exploiting configuration errors that Siemens had already addressed in a security bulletin last month.<\/p>\n<p>&#8220;At this stage, we have not detected an increase in attacks or any previously unknown vulnerabilities&#8221; in the controllers, the company said in a statement from Munich.<\/p>\n<p>The US warning, issued jointly by CISA, the FBI, the National Security Agency, the Department of Energy, the Environmental Protection Agency and the Department of Homeland Security, described an &#8220;active threat&#8221; to all Siemens S7 Series PLCs across manufacturing, energy, water and wastewater, chemical, food and agriculture sectors. The advisory followed a wave of cyberattacks that disrupted more than 30 community water systems in Minnesota beginning Sunday and continuing through Monday, with incidents reported across at least 12 states.<\/p>\n<p>CISA Acting Director Nick Andersen told Recorded Future News that the agency is &#8220;currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,&#8221; emphasizing that &#8220;threat actors are targeting water entities of all sizes.&#8221; The compromises have resulted in boil water notices and forced utilities into sustained manual operations, according to CISA.<\/p>\n<p>AI-Accelerated Exploitation<\/p>\n<p>The advisory marks a notable escalation in how officials characterize the threat, explicitly identifying artificial intelligence as a tool attackers are using to compress the timeline between identifying exposed devices and compromising them. The hackers are using AI-generated exploitation scripts disguised as legitimate monitoring tools to conduct reconnaissance and develop attack capabilities against US-based Siemens installations, according to the advisory.<\/p>\n<p>This approach allows adversaries to scan the internet for vulnerable controllers and generate working exploits far faster than traditional manual methods. Officials described the shift bluntly: &#8220;This is not a theoretical risk \u2014 it is an active threat.&#8221;<\/p>\n<p>The attackers&#8217; playbook focuses on operational disruption rather than data theft. Once inside exposed PLCs, they modify passwords to lock out operators, change IP addresses to disconnect devices from networks, and alter automated settings that force utilities to switch to slower manual control.<\/p>\n<p>Iran Connection Under Investigation<\/p>\n<p>US officials are investigating whether Iran is behind the current wave of water infrastructure attacks. Iranian state-linked hackers operating under personas including CyberAv3ngers have targeted US water systems in multiple campaigns stretching back to 2023. The current advisory stops short of formal attribution, but cybersecurity experts said the operational signatures are consistent with that history.<\/p>\n<p>Officials across the US have reported intrusions at water facilities in Minnesota, Michigan, Arkansas, Georgia and New Jersey in recent months. CISA said the attacks have escalated since Iranian hackers first targeted internet-connected systems used in critical infrastructure.<\/p>\n<p>The Root Problem: Internet-Exposed Controllers<\/p>\n<p>CISA&#8217;s guidance to operators is specific: inventory all Siemens S7 Series PLCs, install available security patches immediately, verify that no controllers are reachable from the public internet, strengthen access controls and authentication, and monitor for anomalous activity. The underlying message is that the fundamental exposure \u2014 critical industrial control systems accessible from the internet \u2014 is a problem patches alone cannot fully address.<\/p>\n<p>&#8220;CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible,&#8221; the agency said in a separate earlier advisory.<\/p>\n<p>Water infrastructure cybersecurity has been a documented vulnerability for years, yet a meaningful share of US water utility PLCs remain internet-exposed, CISA&#8217;s own scans have confirmed even as attacks mount. The combination of aging operational technology, limited cybersecurity budgets at small utilities, and AI-accelerated attack tooling has narrowed the window for remediation considerably.<\/p>\n<p>An incident response professional who works with critical infrastructure told TechCrunch that the use of AI to identify and target vulnerable PLCs was noteworthy, but cautioned that these devices were already highly vulnerable to begin with. Rural communities are often the most affected because their systems service large geographic areas with minimal cybersecurity staffing.<\/p>\n<p>Siemens Response and Divergence<\/p>\n<p>Siemens&#8217; response highlighted a tension between the urgency of the US government&#8217;s warning and the company&#8217;s own assessment. While US agencies described an active and escalating threat, Siemens characterized the advisory as pointing to exploitation of configuration issues it had already flagged in a security bulletin issued last month.<\/p>\n<p>The company did not dispute that its S7 Series controllers are being targeted, but framed the attack vector as misuse of known setup errors rather than exploitation of new vulnerabilities. Siemens said it remains in close communication with CISA and other agencies.<\/p>\n<p>The divergence in tone may reflect different vantage points: US agencies are responding to live incidents at water utilities across the country, while Siemens is monitoring its own threat telemetry from device deployments globally. The company&#8217;s statement did not address whether its own monitoring covers the specific compromise patterns CISA described, such as password modification and IP address changes by attackers.<\/p>\n<p>What is clear is that the S7 Series \u2014 workhorse controllers that have automated industrial processes for decades \u2014 has become a focal point for adversaries targeting US critical infrastructure. Whether the attacks exploit new vulnerabilities or long-standing configuration weaknesses, the practical result for utilities is the same: disrupted operations, manual fallback procedures, and heightened risk to public water supplies.<\/p>\n","protected":false},"excerpt":{"rendered":"Siemens said Wednesday it has not detected an increase in cyberattacks or any previously unknown vulnerabilities in its&hellip;\n","protected":false},"author":2,"featured_media":76363,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21002],"tags":[55685,56306,6077,20244,3146,253,6919,56307,55714,6487,7085],"class_list":["post-76362","post","type-post","status-publish","format-standard","has-post-thumbnail","category-siemens","tag-cisa","tag-cyberav3ngers","tag-department-of-energy","tag-environmental-protection-agency","tag-fbi","tag-iran","tag-national-security-agency","tag-nick-andersen","tag-s7-series-programmable-logic-controllers","tag-siemens","tag-us-department-of-homeland-security"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/76362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/comments?post=76362"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/76362\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media\/76363"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media?parent=76362"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/categories?post=76362"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/tags?post=76362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}