WASHINGTON — August 2026 — The National Security Agency, Cybersecurity and Infrastructure Security Agency, FBI, Department of Energy, and Environmental Protection Agency have issued a joint cybersecurity advisory warning owners and operators of industrial control systems about an active threat targeting Siemens S7 Series programmable logic controllers.
The advisory, titled Defending Against an Active Threat to Siemens S7 Series PLCs, warns that threat actors are conducting reconnaissance and developing capabilities against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The agencies stress that the activity represents an active operational threat rather than a theoretical cybersecurity scenario.
The activity is focused heavily on U.S. critical infrastructure. The sectors most frequently targeted include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Siemens S7 controllers are also used across other sectors, including the Defense Industrial Base, creating a broader exposure beyond the industries already experiencing targeting.
Federal agencies warn that successful compromise of poorly protected PLCs could disrupt industrial processes, create safety incidents, force operational downtime, damage equipment, expose sensitive operational data, trigger regulatory problems, and produce cascading effects across interconnected facilities and supply chains.
The advisory identifies active targeting involving the Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 Series, including multiple CPU variants and F-series safety controllers.
According to the agencies, artificial intelligence is being used to accelerate development of exploitation scripts based on publicly available information concerning Siemens S7 vulnerabilities and weaknesses. The scripts can support initial access, credential compromise, denial-of-service activity, and other objectives against exposed or insufficiently segmented controllers.
The agencies describe AI assistance as a significant change in the threat environment because it reduces the level of technical expertise and development time required to create functional industrial-control-system exploitation tools. AI also allows attackers to modify code rapidly, identify additional attack paths, and adjust their methods as defenders respond.
Threat actors are also using publicly available industrial automation libraries, including snap7.dll and python-snap7, together with AI-assisted scripting to construct tools that imitate legitimate operational-technology monitoring software.
Those tools can provide read-and-write access to Siemens S7 controller memory, configuration information, and ladder-logic programs through the S7comm protocol. This access could allow an intruder to move beyond basic reconnaissance and interact directly with industrial-control functions.
The joint advisory identifies several techniques being observed in the activity.
Threat actors are using Internet-scanning services, including Censys and ZoomEye, to locate Siemens S7 controllers that are exposed directly to the Internet or insufficiently segmented from untrusted networks. They are rapidly developing exploit code with AI assistance, attempting to access controllers protected by default or weak credentials, deploying Python scripts that incorporate Snap7 functionality, disguising malicious scripts as legitimate monitoring utilities, and conducting read-and-write operations against PLC data blocks.
Federal agencies assess that the activity is being used for persistent reconnaissance and capability development against targeted sectors and individual facilities.
Attackers appear to be testing and refining exploitation techniques against specific PLC models to improve their ability to compromise industrial-control environments. Read access can also give attackers information about how a facility operates, potentially positioning them for later write operations capable of disrupting processes or creating other operational effects.
The potential consequences extend beyond temporary loss of access to a computer system.
Unauthorized access to PLCs could interfere with production throughput and product quality, disrupt public services, manipulate safety interlocks or emergency shutdown systems, alter process parameters, damage equipment through improper sequencing or operation outside normal design limits, and expose proprietary process recipes, control strategies, and facility configurations.
The agencies are directing organizations to use a defense-in-depth strategy rather than relying solely on vulnerability patching.
Owners and operators are advised to conduct an immediate inventory of every Siemens S7 Series PLC in their environment and verify firmware versions for S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers.
Organizations should also identify controllers accessible directly or indirectly from untrusted networks and map engineering workstations using Siemens Totally Integrated Automation Portal, STEP 7, or other S7 programming access.
Critical security patches should be applied as quickly as operationally practical. The advisory recommends updating Siemens PLC firmware, prioritizing Internet-facing and demilitarized-zone controllers, updating TIA Portal and STEP 7 software, consulting Siemens ProductCERT advisories, and testing updates in development environments before deploying them into production.
One of the strongest recommendations is to prevent PLCs from being accessible directly from the Internet.
Organizations are advised to audit firewall rules for exposed S7comm services, block TCP port 102 at perimeter firewalls, separate operational-technology and information-technology networks through a demilitarized-zone architecture, deploy unidirectional gateways where appropriate, and verify that unauthorized routing does not exist between corporate and industrial environments.
Access controls should also be strengthened.
The agencies recommend restricting TIA Portal and STEP 7 access to authorized engineering workstations, enabling PLC password protection, configuring appropriate read-and-write protection levels, removing or changing default SNMP community strings, implementing application allowlisting, and requiring multi-factor authentication for remote access to operational-technology networks.
Organizations are also being urged to deploy continuous monitoring tailored specifically to industrial-control environments.
Recommended detection measures include monitoring S7comm traffic on TCP port 102, alerting on unauthorized PUT and GET operations, logging TIA Portal and STEP 7 connections, establishing behavioral baselines, watching for Python processes importing snap7.dll, and detecting sequential IP scanning or abnormal block reads of controller configuration data.
Security teams should also hunt for activity that does not match normal engineering operations.
Potential indicators include connections originating from non-engineering workstations, unusual data-block access, write activity outside approved maintenance windows, repeated connections with changing parameters, unexpected off-hours activity, configuration changes that have no corresponding work order, and connections originating from countries or IP ranges not associated with authorized vendors or integrators.
Additional Siemens-specific hardening measures include disabling unnecessary embedded web servers, turning off unused communication protocols, limiting simultaneous S7comm sessions, enabling available restart and know-how protection functions, and evaluating for ladder-logic changes in online and offline modes.
The agencies warn that organizations relying on system integrators or third-party managed-service providers may face additional exposure because asset owners may not realize external access paths to their PLCs exist. Those organizations are advised to share the advisory with third parties and require implementation of the recommended protections.
The advisory maps the observed activity to multiple MITRE ATT&CK techniques, including scanning open technical databases, exploit development, acquisition of artificial-intelligence capabilities, native API execution, controller-task modification, masquerading, insecure credentials, and collection of data from local systems.
The defensive guidance is also mapped to MITRE D3FEND countermeasures covering hardware inventory, software updates, network isolation, network access mediation, credential hardening, platform monitoring, network traffic analysis, and application-configuration hardening.
The agencies conclude that the combination of known PLC vulnerabilities, publicly available exploitation libraries, Internet exposure, weak configurations, and AI-assisted tool development creates a high-probability attack scenario for inadequately protected Siemens S7 installations.
Organizations are being told to treat the threat with urgency and coordinate defensive action among cybersecurity teams, engineering personnel, plant operations, executive leadership, system integrators, and vendor-support personnel.
U.S. organizations that identify suspicious or criminal activity connected to the threat are encouraged to report incidents to CISA or the FBI. Organizations should preserve information including the date, time, location, type of activity, affected equipment, number of people affected, and organizational contact information when reporting an incident.
The advisory does not publicly identify or attribute the activity to a specific nation-state, criminal organization, or named hacking group. Its central warning is operational: Internet-exposed Siemens S7 PLCs are currently being targeted, and AI-assisted exploitation is reducing the technical barriers attackers face when attempting to compromise industrial-control systems.
Joint Cybersecurity Advisory issued by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), U.S. Department of Energy (DOE), and U.S. Environmental Protection Agency (EPA), August 2026.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



