CiberLATAMbywhalemate

CISA warns on active Siemens S7 PLCs

CISA expanded its alert on Siemens S7 PLCs and said more than 100 water systems were hit in July, with limited but real impacts.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

CISA raised the number of water and wastewater systems hit in July to more than 100 and confirmed limited operational impacts, including PLC password changes, IP reassignment and temporary manual operations at some plants.

Update August 30, 2026: CISA and media coverage expanded the scope of the campaign to more than 100 water and wastewater systems attacked in July. New details also emerged on limited operational impacts, an expanded advisory covering more PLC models, and a separate investigation into a Micro-Comm breach.

CISA issued an industrial alert on August 20, 2026, about an active threat against Siemens S7 programmable logic controllers used across several U.S. critical infrastructure sectors, including energy, water and wastewater, manufacturing, chemicals, food and agriculture. The alert came with a joint advisory from federal agencies and sector bulletins calling for immediate hardening measures in OT environments.

What did the federal advisory say about Siemens S7?

The advisory, AA26-231A, issued by NSA, CISA, FBI, DOE and EPA, identified Siemens S7-200, S7-300, S7-400, S7-1200 and S7-1500 models as affected, including S-series safety controllers, and said the risk applies to all PLC owners, regardless of the type of ICS or OT installation. State and industry association bulletins repeated the notice with direct contact lines to CISA, including 1-844-Say-CISA, and with summaries of priority mitigations for water and wastewater utilities.

What techniques are the attackers using?

Agencies and technical reporting describe a chain that combines public reconnaissance with AI automation. According to the advisory and cited analyses, the actors use Internet scanning services such as Censys and ZoomEye to find Siemens S7 PLCs with port 102 exposed, then generate Python exploitation scripts with artificial intelligence tools. TechTimes also said the exploits rely on open source libraries such as snap7 and python-snap7, and that the federal notice cites unauthorized use of snap7.dll outside approved systems as an indicator of compromise.

The same coverage says this is the first official U.S. advisory to explicitly acknowledge AI-generated code being used to write exploits against Siemens S7 PLCs deployed in water, energy, chemical and manufacturing plants. TechCrunch also reported that the agencies warned about scripts based on publicly available Siemens S7 information, with a focus on outdated or poorly protected equipment.

How did the scope change in water systems?

CISA and outlets including TechCrunch, SecureWorld and TechRadar Pro reported that the campaign reached more than 100 water and wastewater systems in July, although it did not cause significant outages. Observed effects included unauthorized PLC password changes, IP address reassignment, boil-water notices and the need to run some plants manually to maintain service.

According to TechCrunch, CISA's advisory said the attackers did not cause significant damage, but they did alter settings on exposed equipment and forced some utilities to move temporarily to manual operation. SecureWorld added that CISA issued specific guidance to reduce PLC exposure to the Internet through asset inventory, removal of unnecessary access, credential changes for default passwords, patching and MFA.

TechRadar Pro said the reported impacts included unauthorized PLC password changes, IP address changes, boil-water notices and temporary manual operation. The outlet also said attribution remains uncertain, although some investigations point to a possible Iranian group.

What happened at Clayton County Water Authority?

The July 27 case at Clayton County Water Authority had a visible but limited impact on customers. Facilities Dive reported that officials issued a boil-water notice while they checked water quality and that normal service was restored within hours, once the water was confirmed safe.

What changed in the July advisory?

The original joint CISA and FBI advisory on attacks against Rockwell PLCs was updated on July 22 to extend the scope to Siemens S7-1200 and Schneider Electric Modicon M340 PLCs. WaterOnline also said attackers began using legitimate manufacturer engineering software to steal project files and manipulate control logic, a technical escalation beyond simply scanning exposed devices.

EBuilderSecurity said advisory AA26-097A, issued on April 7 and updated on July 22, links the campaign targeting exposed PLCs to the IRGC Cyber Electronic Command and the CyberAv3ngers group, known for earlier compromises of Unitronics controllers at U.S. water facilities in 2023. CISA's public communication, however, uses a more cautious attribution.

How did authorities ask operators to respond?

CISA and its partners urged operators to remove Siemens S7 PLCs that are directly exposed to the Internet, inventory all S7 devices, apply critical patches, strengthen access controls, monitor for unauthorized activity and harden services, protocols and ladder logic integrity. WaterISAC consolidated the alert in TLP:CLEAR bulletins and asked operators to review which specific devices in their ICS and SCADA environments are covered and apply targeted mitigations.

Yahoo News summed up the operational guidance in a checklist for utilities: disconnect PLCs from the Internet, route all remote access through a VPN or secure gateway, change default passwords and use access control lists to limit connections to authorized devices only.

The sector response also extended to Minnesota. Regional coverage said more than 30 community water utilities in the state were targeted in a coordinated campaign on July 26 and 27, while federal and state authorities investigate attacks on water and wastewater treatment facilities in several U.S. states. Teknopolitika added that the response included activation of the state's cyber incident response capabilities and coordination among the Minnesota Department of Public Safety, the Minnesota Fusion Center, the Department of Health, the Pollution Control Agency, CISA, EPA, FBI and local utilities.

Is attribution confirmed?

There is no confirmed formal attribution in the material provided. Security Boulevard described the wave of attacks against operational technology at U.S. water utilities and said some researchers view it as possibly linked to Iran, but without official confirmation. OPSWAT, in a sector analysis, said federal authorities would have preliminarily pointed to Iran as the main suspect behind the attacks in Minnesota and Michigan, while stressing that attribution remains preliminary and that the FBI's investigation is still open.

Reuters also reported that U.S. authorities are investigating a data breach at Micro-Comm, a small Kansas supplier that provides control technology to water and wastewater utilities. According to that coverage, the incident appears linked to a separate ransomware attack from the campaign suspiciously associated with Iranian actors against plants in Minnesota and other states.

Sources

View all