US government agencies have warned that unidentified hackers are actively attempting to compromise Siemens S7 Series programmable logic controllers used across critical infrastructure.
The joint advisory was issued by the FBI, NSA, Department of Energy, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency (CISA). The affected controllers are used in sectors including water and wastewater, energy, manufacturing, chemicals, food, and agriculture.
Authorities warned that successful compromises could disrupt critical processes, cause downtime or equipment damage, expose sensitive information, and potentially create safety risks. The consequences would depend on the systems targeted and the level of access obtained by the attackers.
The agencies also reported that threat actors are using artificial intelligence to accelerate the development of attack tools. According to the advisory, AI can reduce both the technical expertise and time needed to create exploits capable of compromising industrial systems.
The warning comes amid increased malicious activity targeting programmable logic controllers in the US. CISA reported a significant rise in attacks against PLCs on July 30.
Several days earlier, US authorities had warned that Iranian-affiliated hackers were targeting industrial controllers manufactured by Siemens, Rockwell Automation, and Schneider Electric.
However, the hackers behind the latest attacks against Siemens S7 controllers have not been publicly identified, and authorities have not formally connected the activity to Iran.
The alert also follows a series of cyber incidents affecting local water systems across several US states. At least 30 water-related incidents were reported in Minnesota on July 26 and July 27, with additional attacks subsequently affecting water infrastructure elsewhere.
Cybersecurity experts have suspected Iranian involvement in some of the recent activity, but US officials have not formally attributed the latest water-system attacks to Iranian actors.
The current federal advisory therefore identifies an active threat to Siemens S7 Series controllers without assigning responsibility to a specific country or hacking group. The warning covers multiple critical infrastructure sectors, with water and wastewater systems among the environments potentially at risk.