NSA, FBI Warn of AI-Powered Attacks on Siemens PLCs
NSA and FBI warn that AI-generated scripts are actively targeting Siemens S7 PLCs in U.S. critical infrastructure. Inventory, segment, and patch now.

The Siemens S7 Series PLC has been a fixture of industrial control environments for decades. Power substations, water treatment facilities, manufacturing lines — the S7-300 and S7-400 generations are still running the physical layer in facilities that have outlasted several generations of security guidance without a meaningful hardware refresh.
That installed base is now a formally documented target.
The National Security Agency (NSA), FBI, and partner federal agencies published a joint advisory on August 19 warning that threat actors are targeting Siemens S7 Series PLCs deployed in U.S. critical infrastructure using AI-generated scripts to exploit known vulnerabilities. The Record confirmed the advisory describes a campaign fueled by “AI-assisted development” alongside exploitation of existing flaws in the S7 product line.
What Changes With AI-Generated Tooling
The advisory isn’t describing a new vulnerability class. What NSA and FBI are flagging is operational: AI-generated scripting reduces the skill floor for targeting PLC hardware that was never designed with adversarial network exposure in mind.
Siemens S7 devices communicate over proprietary protocols on TCP port 102. The research community has documented weaknesses in those protocols for well over a decade. What has historically limited widespread exploitation is the specialized knowledge required to operationalize those findings against specific firmware versions and configurations. AI-generated tooling erodes that barrier.
Specific CVEs are not named in the advisory as reported. The agencies describe exploitation of “known vulnerabilities” in the S7 line — which means any outstanding Siemens patches in your environment are now higher priority than they were yesterday.
What to Do
If Siemens S7 hardware is in your environment:
- Complete your firmware inventory now. Know what versions are running, and where. If you don’t know, this advisory is the reason to find out today.
- Enforce network segmentation. TCP port 102 should not be reachable from corporate networks or anything outside a dedicated OT segment. If it is, that is the first thing to fix.
- Apply outstanding Siemens patches. ICS Patch Tuesday this month included fixes across multiple S7 product lines.
- Cross-reference CISA KEV. Any Siemens CVE on the Known Exploited Vulnerabilities catalog should be treated as under active pressure.
Context
This advisory follows a consistent pattern of federal warnings about OT infrastructure under sustained attack. Iranian actors hit multistate water treatment PLCs this month. CISA warned of rising attacks on water utility PLCs in July. The addition of AI-generated tooling as an explicit element in this campaign signals a durable shift in the threat environment — not a one-off incident to be filed and forgotten.
The full advisory is available via CISA’s ICS resources. Read the primary source.
Found this useful? Share it.


