PLC Siemens sotto attacco: l’AI accelera la ricognizione contro le infrastrutture critiche
AI

Illustrative image generated with AI

Siemens PLCs Under Attack: AI Accelerates Reconnaissance Against Critical Infrastructure

Federal alert: AI speeds reconnaissance of Siemens PLCs in critical infrastructure, enabling attacks that threaten operational control.

Text generated by artificial intelligence, published without human review. AI transparency

Federal Alert on an Already Active Threat

The NSA, FBI, and other U.S. federal agencies have issued an alert about reconnaissance activity targeting organizations that operate critical infrastructure. The document, identified as AA26-231A, focuses in particular on Siemens S7-series PLCs.

The advisory urges operators to act immediately. It does not describe a purely theoretical scenario: threat actors are already searching for exposed Siemens devices and developing tools to exploit their weaknesses.

PLCs, or programmable logic controllers, control physical equipment and processes. They can manage pumps, valves, motors, and production lines, while also collecting data about how a facility operates. Unauthorized access therefore involves more than compromising a computer: it can result in the loss of operational control over an industrial process.

The advisory does not attribute the campaign to a specific criminal group or country. The agencies refer to unidentified actors targeting Siemens installations in the United States.

How the Attackers Operate

The first observed phase is reconnaissance. Attackers use Internet-scanning platforms to identify PLCs directly reachable from the public Internet—a risky configuration for any operational technology system.

Once devices are discovered, operators can gather information about the environment, search for known vulnerabilities, and identify potential paths to credentials or other connected systems. Exploit scripts are also disguised as legitimate operational monitoring tools.

This technique is designed to blend in with routine administration and supervisory activity. A malicious tool may appear to be a program intended to check the status of a facility, while actually attempting to gain access, escalate privileges, or prepare further actions.

According to the alert, the immediate objective appears to be maintaining a presence in selected facilities. Reconnaissance would allow attackers to understand networks, devices, and processes before attempting actions with physical consequences.

The sequence is significant. If the group completes the preparatory phase without being detected, a subsequent attack could require limited resources.

The Role of Artificial Intelligence

Artificial intelligence is being used to generate scripts capable of interacting with PLCs, exploiting vulnerabilities, and obtaining credentials or additional access paths. U.S. agencies believe this approach reduces both the expertise required and the time needed to produce working code targeting industrial systems.

AI can also rapidly modify tools in response to countermeasures. If an organization blocks a behavior or recognizes a particular signature, attackers can attempt to create a variant that is harder to distinguish from legitimate software.

Brian Proctor, CEO of OT penetration-testing company Frenos, highlighted the reduction in time between the disclosure of a vulnerability and the availability of a usable script. Someone without sufficient exploit-development experience could therefore gain significant operational support.

In industrial environments, the problem is not limited to speed. OT systems are often heterogeneous, long-lived, and connected to physical processes that cannot easily be taken offline. The ability to generate customized tools therefore increases the number of actors potentially capable of attempting an intrusion.

The use of AI does not mean that every phase is automated. Network access, knowledge of the facility, and the ability to select targets are still required. However, the technology can dramatically compress preparation times.

Which Facilities Are Exposed

Siemens S7 PLCs are used across numerous sectors:

  • power generation and distribution;
  • water treatment and distribution;
  • agriculture;
  • manufacturing;
  • the defense industry.

The risk may affect both directly exposed devices and systems connected to their OT networks. A compromised PLC could enable attackers to alter parameters, interrupt processes, or steal information about a facility.

Specific versions of the affected Siemens products have not been disclosed. The alert also does not identify a single vulnerability or CVE associated with the campaign. Based on the available information, it is therefore impossible to determine which releases are vulnerable or whether the activity exploits a single flaw.

The threat extends beyond Siemens. In July, federal agencies reported activity attributed to Iran-linked actors targeting PLCs from Schneider Electric, Rockwell Automation, and Allen-Bradley, as well as Siemens devices.

Two weeks ago, dozens of water utilities across at least 12 states reported intrusions targeting PLCs and attributed to suspected Iranian operators. The new alert appears to expand the scope beyond water facilities to include other industrial sectors and critical infrastructure.

Potential Impact Goes Beyond Data Theft

An attack on a PLC can halt a process, damage equipment, or cause a prolonged operational outage. In certain environments, it may also create conditions for safety incidents.

The alert highlights a particularly concerning scenario: personnel could lose visibility into the physical process while that process continues to operate. The control room would no longer accurately reflect the facility’s status and would be unable to respond promptly.

The effects could spread to interconnected systems, causing cascading consequences. Sensitive data could also be compromised and compliance obligations violated, but the primary damage may be operational rather than informational.

Another risk involves suppliers. An organization may believe that it has no directly accessible PLCs, only to discover that exposure was introduced by an integrator, maintenance provider, or technology partner.

The CISA Known Exploited Vulnerabilities (KEV) Catalog is not mentioned in the available alert. It is therefore unknown whether a specific vulnerability linked to this activity has been added to the catalog, or whether an associated date of inclusion or remediation deadline exists.

Priorities for OT Operators

The first step is to eliminate direct Internet exposure of PLCs whenever it is not essential. Remote access should use controlled architectures with network segmentation, strong authentication, and monitoring.

Organizations should also:

  1. install all available patches for PLCs and related components;
  2. inventory Siemens S7 devices and other controllers deployed across their facilities;
  3. assess exposure introduced by vendors and integrators;
  4. deploy monitoring tools capable of detecting scanning and anomalous behavior;
  5. search for software that imitates legitimate supervisory tools;
  6. prepare procedures for operating if process visibility or control is lost.

The response should not be limited to the IT network. Teams must also review OT configurations, maintenance-provider access, connections between network segments, and supervisory systems.

The recommendations in alert AA26-231A should also be applied to environments using Schneider Electric, Rockwell Automation, and Allen-Bradley PLCs. The campaign targeting Siemens appears to be one component of a broader threat, rather than an isolated incident.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsSiemens PLCsAI attackscritical infrastructurereconnaissanceindustrial control systemscybersecurityfederal alertOT security
Back to home