{"id":77324,"date":"2026-08-23T04:58:38","date_gmt":"2026-08-23T04:58:38","guid":{"rendered":"https:\/\/www.europesays.com\/germany\/77324\/"},"modified":"2026-08-23T04:58:38","modified_gmt":"2026-08-23T04:58:38","slug":"ai-fueled-attacks-pose-active-threat-to-water-other-sectors-u-s-agencies-warn","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/germany\/77324\/","title":{"rendered":"AI-fueled attacks pose \u2018active threat\u2019 to water, other sectors, U.S. agencies warn"},"content":{"rendered":"<p>Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday.<\/p>\n<p>It\u2019s the latest government warning about <a href=\"https:\/\/cyberscoop.com\/trump-blames-minnesota-water-cyberattacks-iran\/\" rel=\"nofollow noopener\" target=\"_blank\">attacks on critical infrastructure<\/a> as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems\u2014 but doesn\u2019t mention in Wednesday\u2019s alert.\u00a0<\/p>\n<p>The National Security Agency didn\u2019t immediately respond to a request for comment about who was behind the attacks on the PLCs, which are used to control manufacturing processes.<\/p>\n<p>The agencies said the attacks were an \u201cactive threat,\u201d rather than a theoretical one. The attacks could disrupt critical industrial processes, cause safety incidents or lead to the compromise of sensitive data.<\/p>\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-231a?utm_source=SiemensS7SeriesPLC&amp;utm_medium=GovDelivery\" rel=\"nofollow noopener\" target=\"_blank\">Wednesday\u2019s alert<\/a> from the NSA, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department and Environmental Protection Agency makes special note of the hackers using AI-generated exploitation scripts in the attacks.<\/p>\n<p>\u201cUsing AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,\u201d the alert states. \u201cIn addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.\u201d<\/p>\n<p>A former top CISA official, Michael Garcia, thought that it was a first for the agency in one of its cybersecurity advisories (CSAs) about operational technology (OT).<\/p>\n<p>\u201cIt is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems,\u201d Garcia, now vice president of the cybersecurity practice at Monument Policy Advocacy, <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7495873382983340033\/\" rel=\"nofollow noopener\" target=\"_blank\">said on LinkedIn<\/a>. But the advisory doesn\u2019t recommend using AI in response, instead focusing on well-known, traditional defensive measures, he added.<\/p>\n<p>Frenos, an OT penetration testing company, found another element of the alert troubling: The method by which the attackers could use the approach beyond Siemens-made PLCs.<\/p>\n<p>\u201cSiemens S7 is the subject here, but the exposure pattern is not brand specific,\u201d Brian Proctor, CEO of the company, said in an email. \u201cAn adversary who has mapped your data blocks understands your process. They know what normal looks like, which means they know what an operator would fail to notice.\u201d<\/p>\n<p>The AI-generated scripts are disguised as legitimate monitoring tools, the advisory said of the hackers behind them.<\/p>\n<p>\u201cThe actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,\u201d the advisory reads.<\/p>\n<p>Siemens said it was \u201caware\u201d of the alert and \u201cis coordinating closely with CISA.\u201d<\/p>\n<p>\u201cThis advisory does not describe new vulnerabilities within the S7 Series programmable logic controllers (PLC). Instead, this reflects threat actors employing new techniques to exploit potential misconfigurations,\u201d the company continued, noting a <a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssb-104599.html\" rel=\"nofollow noopener\" target=\"_blank\">security bulletin<\/a> it issued last month.<\/p>\n<p>\u201cSiemens will provide updates around this issue to potentially affected customers through our ProductCERT team,\u201d it said. \u201cAt this point in time, we have not identified increased attack levels or unknown vulnerabilities in Siemens ICS products.\u201d<\/p>\n<p>Updated 8\/20\/2026: to include Siemens comment.<\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/www.europesays.com\/germany\/wp-content\/uploads\/2026\/08\/Tim-Starks-01.jpg\" alt=\"Tim Starks\"\/><\/p>\n<p>\t\t\tWritten by Tim Starks<br \/>\n\t\t\tTim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he&#8217;s covered cybersecurity since 2003. Email Tim here: <a href=\"https:\/\/cyberscoop.com\/hackers-use-ai-target-siemens-plcs-critical-infrastructure\/mailto:tim.starks@cyberscoop.com\" rel=\"nofollow noopener\" target=\"_blank\">tim.starks@cyberscoop.com<\/a>.\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series&hellip;\n","protected":false},"author":2,"featured_media":77325,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21002],"tags":[22513,56801,56802,56803,1646,56804,56805,40904,253,2695,56806,56807,55599,6487,56808],"class_list":["post-77324","post","type-post","status-publish","format-standard","has-post-thumbnail","category-siemens","tag-artificial-intelligence-ai","tag-chemical-plants","tag-cybersecurity-and-infrastructure-security-agency-cisa","tag-department-of-energy-doe","tag-energy","tag-environmental-protection-agency-epa","tag-federal-bureau-of-investigation-fbi","tag-food-security","tag-iran","tag-manufacturing","tag-national-security-agency-nsa","tag-operational-technology","tag-programmable-logic-controllers","tag-siemens","tag-water-sector"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/77324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/comments?post=77324"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/77324\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media\/77325"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media?parent=77324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/categories?post=77324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/tags?post=77324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}