08/20/2026
🚨Cybersecurity Alert!🚨
Cybersecurity and Infrastructure Security Agency, in conjunction with the U.S. Environmental Protection Agency, NSA - National Security Agency, FBI – Federal Bureau of Investigation, and U.S. Department of Energy have released this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them.
Threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected.
Owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:
are properly protected with all applicable security patches and updates,
are isolated from the Internet wherever possible,
have strong access controls, and
employ security tooling to monitor ICS environments for anomalous or malicious activity.
These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.
These agencies recommend that utility operators review the tactics, techniques, and procedures (TTPs) in this cybersecurity advisory and conduct recommended mitigation and preventative actions to reduce the likelihood of an attack.
This advisory warns of threat actors targeting Siemens S7 Series programmable logic controllers (PLCs) and includes mitigations to be understood and applied within the broader context of ongoing threats to PLCs and operational technology devices.