CISA warns of active Siemens S7 PLC threat
CISA and federal agencies issued an alert on an active threat to Siemens S7 PLCs used in water, energy, and other critical sectors.
On Aug. 20, 2026, CISA issued an industrial alert on an active threat targeting Siemens S7 programmable logic controllers used across multiple U.S. critical infrastructure sectors, including energy, water and wastewater, manufacturing, chemicals, food and agriculture. The warning was backed by NSA, FBI, DOE and EPA, along with sector advisories calling for urgent hardening steps in OT environments.
CISA published an industrial alert on Aug. 20, 2026, warning of an active threat targeting Siemens S7 programmable logic controllers used across multiple U.S. critical infrastructure sectors, including energy, water and wastewater, manufacturing, chemicals, food and agriculture. The alert was accompanied by a joint advisory from federal agencies and sector bulletins calling for immediate hardening measures in OT environments.
What did the federal advisory say about Siemens S7?
Advisory AA26-231A, issued by NSA, CISA, FBI, DOE and EPA, identified Siemens S7-200, S7-300, S7-400, S7-1200 and S7-1500 models as affected, including F-series safety controllers, and said the risk applies to all PLC owners regardless of the ICS/OT installation type. State bulletins and notices from water-sector associations repeated the alert with direct contact lines to CISA, such as 1-844-Say-CISA, and summaries of priority mitigations for water and wastewater utilities.
What techniques are attackers using?
The agencies and technical coverage describe a chain that combines public reconnaissance with AI automation. According to the advisory and cited analysis, threat actors are using internet scanning services such as Censys and ZoomEye to locate Siemens S7 PLCs with port 102 exposed, then generating Python exploit scripts with artificial intelligence tools. TechTimes also reported that the exploits rely on open source libraries such as snap7 and python-snap7, and that the federal notice includes unauthorized use of snap7.dll outside approved systems as an indicator of compromise.
The same coverage says this is the first official U.S. advisory to explicitly acknowledge the use of AI-generated code to write exploits against Siemens S7 PLCs deployed in water, energy, chemicals and manufacturing plants. TechCrunch also reported that the agencies warned about scripts based on public information about Siemens S7, with a focus on outdated or poorly protected equipment.
How did authorities ask operators to respond?
CISA and its partners urged operators to remove Siemens S7 PLCs exposed directly to the internet, inventory all S7 equipment, apply critical patches, strengthen access controls, monitor for unauthorized activity and harden services, protocols and ladder logic integrity. WaterISAC consolidated the alert in TLP:CLEAR bulletins and asked operators to review which specific devices in their ICS/SCADA environments are included and apply targeted mitigations.
The sector response also extended to Minnesota. Regional coverage detailed that more than 30 community water utilities in the state were targeted in a coordinated campaign on July 26 and 27, while federal and state authorities investigate attacks against water and wastewater treatment facilities in several U.S. states. Teknopolitika added that the response included activation of the state's cyber incident response capabilities and coordination among the Minnesota Department of Public Safety, the Minnesota Fusion Center, the Department of Health, the Pollution Control Agency, CISA, EPA, FBI and local utilities.
Is attribution confirmed?
There is no confirmed formal attribution in the material provided. Security Boulevard described the wave of attacks against water utility operational technology in the United States and said some researchers consider it possibly linked to Iran, but without official confirmation. OPSWAT, in a sector analysis, said federal authorities would have preliminarily pointed to Iran as the main suspect behind the attacks in Minnesota and Michigan, although it clarified that attribution remains preliminary and that the FBI is keeping the investigation open.
Sources
- US agencies warn of AI-powered attacks on Siemens ...helpnetsecurity.com· Help Net Security
- Recent Water Utility Attacks Show Why OT Security Can’t Waitsecurityboulevard.com· Security BoulevardUnverified URL
- Feds Confirm AI Is Writing Exploits for Siemens PLCs Used ...techtimes.com· TechTimes
- What we know so far about the hacking campaign against US water systemscybersecuritydive.com· Cybersecurity Dive
- ACWA Weekly Wrap Vol. XVII, Issue 26 (Week of August 17, 2026)acwa-us.org· ACWA
- Cybersecurity: Active Threat to Siemens S7 Series PLCscontent.govdelivery.com· Virginia Department of Health
- Cybersecurity: Active Threat to Siemens S7 Series PLCscontent.govdelivery.com· Washington State Department of Health
- EUA alertam que dispositivos da Siemens podem ser hackeados em meio a temores de que Irã esteja invadindo estações de tratamento de águabr.investing.com· Reuters via Investing.comUnverified URL
- More than 30 Minnesota water systems targeted in coordinated cyberattackteknopolitika.org· Teknopolitika
- US says hackers are targeting vulnerable water systems with the help of AItechcrunch.com· TechCrunch
- CISA and partners issue advisory on active threat to Siemens programmable logic controllerinsidecybersecurity.com· Inside Cybersecurity
- Coordinated Attacks on U.S. Water Systems via Exposed ...cyware.com· Cyware
- Could a Cyberattack Shut Down Your Water System? Minnesota Cyberattack Signals Operational Riskballardspahr.com· Ballard Spahr
- FBI Issue Warning on IoT & OT Vulnerabilitiesiotm2mcouncil.org· IoT M2M Council
- Les attaques contre l'approvisionnement en eau dans le Minnesota et le Michigan ne sont pas une surprisefrench.opswat.com· OPSWATUnverified URL
- (TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates and Bulletins - August 20, 2026waterisac.org· WaterISAC



