CiberLATAMbywhalemate

CISA warns of active Siemens S7 PLC threat

CISA and federal agencies issued an alert on an active threat to Siemens S7 PLCs used in water, energy, and other critical sectors.

Whalemate Labs · AI-assisted researchPublished:4 min read

On Aug. 20, 2026, CISA issued an industrial alert on an active threat targeting Siemens S7 programmable logic controllers used across multiple U.S. critical infrastructure sectors, including energy, water and wastewater, manufacturing, chemicals, food and agriculture. The warning was backed by NSA, FBI, DOE and EPA, along with sector advisories calling for urgent hardening steps in OT environments.

CISA published an industrial alert on Aug. 20, 2026, warning of an active threat targeting Siemens S7 programmable logic controllers used across multiple U.S. critical infrastructure sectors, including energy, water and wastewater, manufacturing, chemicals, food and agriculture. The alert was accompanied by a joint advisory from federal agencies and sector bulletins calling for immediate hardening measures in OT environments.

What did the federal advisory say about Siemens S7?

Advisory AA26-231A, issued by NSA, CISA, FBI, DOE and EPA, identified Siemens S7-200, S7-300, S7-400, S7-1200 and S7-1500 models as affected, including F-series safety controllers, and said the risk applies to all PLC owners regardless of the ICS/OT installation type. State bulletins and notices from water-sector associations repeated the alert with direct contact lines to CISA, such as 1-844-Say-CISA, and summaries of priority mitigations for water and wastewater utilities.

What techniques are attackers using?

The agencies and technical coverage describe a chain that combines public reconnaissance with AI automation. According to the advisory and cited analysis, threat actors are using internet scanning services such as Censys and ZoomEye to locate Siemens S7 PLCs with port 102 exposed, then generating Python exploit scripts with artificial intelligence tools. TechTimes also reported that the exploits rely on open source libraries such as snap7 and python-snap7, and that the federal notice includes unauthorized use of snap7.dll outside approved systems as an indicator of compromise.

The same coverage says this is the first official U.S. advisory to explicitly acknowledge the use of AI-generated code to write exploits against Siemens S7 PLCs deployed in water, energy, chemicals and manufacturing plants. TechCrunch also reported that the agencies warned about scripts based on public information about Siemens S7, with a focus on outdated or poorly protected equipment.

How did authorities ask operators to respond?

CISA and its partners urged operators to remove Siemens S7 PLCs exposed directly to the internet, inventory all S7 equipment, apply critical patches, strengthen access controls, monitor for unauthorized activity and harden services, protocols and ladder logic integrity. WaterISAC consolidated the alert in TLP:CLEAR bulletins and asked operators to review which specific devices in their ICS/SCADA environments are included and apply targeted mitigations.

The sector response also extended to Minnesota. Regional coverage detailed that more than 30 community water utilities in the state were targeted in a coordinated campaign on July 26 and 27, while federal and state authorities investigate attacks against water and wastewater treatment facilities in several U.S. states. Teknopolitika added that the response included activation of the state's cyber incident response capabilities and coordination among the Minnesota Department of Public Safety, the Minnesota Fusion Center, the Department of Health, the Pollution Control Agency, CISA, EPA, FBI and local utilities.

Is attribution confirmed?

There is no confirmed formal attribution in the material provided. Security Boulevard described the wave of attacks against water utility operational technology in the United States and said some researchers consider it possibly linked to Iran, but without official confirmation. OPSWAT, in a sector analysis, said federal authorities would have preliminarily pointed to Iran as the main suspect behind the attacks in Minnesota and Michigan, although it clarified that attribution remains preliminary and that the FBI is keeping the investigation open.

Sources

View all