U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs

The S7 Series is part of a family of programmable logic controllers that are used widely in manufacturing and in critical U.S. infrastructure. The intrusions follow warnings, including those on this site, that AI is supercharging cyberattacks on plant gear.

What you’ll learn:

  • Multiple U.S. investigative agencies said cyberattackers used AI-generated code to target Siemens S7 Series PLCs, these in U.S. critical infrastructure.
  • The multi-agency advisory stated that the as-yet-unidentified attackers are using AI to develop Python exploitation scripts that use the 'snap7.dll' and 'python-snap7' libraries.
  • The reports follow an episode last fall when vulnerabilities were discovered in the Siemens RuggedCom ROXOS II multiservice platform but not exploited by threat actors, thanks to detection and patching.

Far be it for us to toot our own horn, but we'll do so anyway: AI-powered cyberattacks on manufacturing and critical infrastructure are a thing, a very big thing. And we and our contributing writers have been telling you so for more than a minute. The latest news provides more proof.

Dennis Scimeca grabbed this for our brands last week, based on advisories reflected at tech and cybersecurity news website BleepingComputer: Siemens manufacturing and critical infrastructure hardware has been coming under assault from cyberattackers, who most notably used AI-generated code to do so.

See also: AI is superpowering cyberattacks, but manufacturers can cut their exposure

The details: The U.S. National Security Agency, the FBI, the U.S. Department of Energy, the U.S. Environmental Protection Agency, and the U.S. Cybersecurity and Infrastructure Agency all jointly announced that cyberattackers had used or are using AI-generated code to target Siemens S7 Series programmable logic controllers, these specific ones embedded into critical infrastructure.

Many of you are “boots-on-the-ground” in OT or IT so you know that PLCs are vitally important plant gear—and those from Siemens are some of the most widely used in manufacturing and other sectors.

PLCs are the rugged, reliable brains that monitor inputs from sensors, execute custom user logic, and control physical outputs like motors, valves, and lights to automate machinery and factory processes. They control assembly lines, water treatment facilities, power grids, and even everyday infrastructure like traffic lights and elevators.

Cyberattackers used or are using AI-generated code to target Siemens S7 Series programmable logic controllers.

The several "federal agencies co-signing this advisory tells you how seriously they view the exposure, especially given the defense industrial base angle," said Frank Balonis, who is field chief information security officer and a recognized SME in data security at Kiteworks, vendor of cybersecurity software.

"The underlying failure is rarely the PLC itself. It's internet-facing devices, weak authentication, and no clear inventory of what's actually exposed." 

Balonis also added this warning: "Until organizations can answer 'who and what can reach this system' with confidence, patching alone won't close the gap."

See also: AI ‘governance gap’ persists as security incidents continue to rise

To get technical about the cyberattack itself, the multi-agency advisory said the as-yet-unidentified attackers are using AI to develop Python exploitation scripts that use the "snap7.dll" and "python-snap7" libraries to communicate with Siemens S7 PLC devices, according to BleepingComputer.

The targeted Siemens PLCs include the S7-200, S7-300, S7-400, S7-1200 and S7-1500 models.

The underlying failure is rarely the PLC itself. It's internet-facing devices, weak authentication, and no clear inventory of what's actually exposed.

- Frank Balonis, field CISO for Kiteworks

If cyberattacks (or potential ones) on plant controllers sound familiar, contributor Trae Mazza, a senior security engineer at RMC Global, last fall detailed exclusively for Smart Industry two hidden gaps in Siemens’ RuggedCom ROXOS II multiservice platforms that were identified and patched, heading off possible penetration by threat actors.

And our Sarah Mattalian has been doing on-point reporting since 2025 turned to 2026 on numerous cybersecurity subjects, including an MxD workshop in Chicago where industrial stakeholders simulated ransomware attack scenarios (the kind manufacturers face most often) and observed strategies to implement before, during, and after data is stolen or systems are manipulated.

And, speaking of the current subject of AI-powered attacks, she followed a Darktrace report in June that also exposed more facets of the growing cybersecurity risks manufacturers face from AI.

More particulars of PLC cyberattacks and some defenses

According to BleepingComputer via IndustryWeek's Dennis Scimeca, the custom AI-generated attack tools work by continuously monitoring PLCs, looking for vulnerabilities and possibly preparing threat actors to launch the attacks that could steal data, shut down equipment on the floor, or otherwise interrupt normal operations.

See also: How one form of AI is hypercharging cyberattacks on manufacturing

According to CISA, top mitigation strategies include inventorying all Siemens PLCs, applying security patches, making sure PLCs cannot access the internet, and monitoring for unauthorized activity or anomalies that may indicate compromised security.

Kiteworks' Frank Balonis added: "What's notable here isn't that Siemens PLCs are being targeted; that's been happening for years. It's how fast attackers can now build custom reconnaissance tools using AI-generated code. That compresses the timeline between 'someone scanned our network' and 'someone has a working exploit,' which means organizations can no longer treat OT monitoring as a quarterly checklist item."

See also: Smart Industry cybersecurity e-book

This news about the Siemens PLC intrusion and the resulting multi-agency advisory follows closely behind cyberattacks on GE, Philips, Shell, and 40 other companies that reportedly targeted a specific vulnerability in software commonly used by manufacturers, product lifecycle management tools, or PLMs, these specifically from vendor PTC.

It also comes soon after coordinated incursions in late July, on other programmable logic controllers, that disrupted water utilities in 30-plus Minnesota communities. Iranian cyberattackers are suspected of being responsible for those break-ins.

Siemens weighs in

For its part, Siemens is keeping comms open and updated about its targeted industrial control systems, including posting any relevant government advice as well as its own bulletins.

Late last week, the company once again updated a year-old advisory on cyberthreats to its ICS. This included more information and mitigation strategies to help customers shield S7 Series programmable logic controllers (two other updates to the same advisory regarding its PLCs were posted in April and July of this year).

See also: Data breaches escalate to records amid slow disclosure by supply chain companies

And in a separate Aug. 21 email, Siemens was forthcoming with an Aug. 19 CISA advisory specifically on the “active threat” to the company’s S7 PLCs, with much more detailed advice on protecting these popular industrial devices from cyberattacks.

“This [CISA] advisory does not describe new vulnerabilities within the S7 Series programmable logic controllers,” Siemens noted in its email to Smart Industry. “Instead, this reflects threat actors employing new techniques to exploit potential misconfigurations or insecure operations that Siemens identified recently in the Siemens Security Bulletin.”

The “new techniques,” a company spokesman confirmed, does refer at least in part to the attacks of late that reportedly utilized AI-generated code.

AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures.

- U.S. Cybersecurity and Infrastructure Agency

He also noted that the CISA advisory states this, which puts the problem of AI-assisted cyberattacks in stark perspective: “Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools."

The CISA advisory continues: “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the internet, they are at high risk for exploitation.”

Also in its note to us, Siemens promised to advise customers through its special ProductCERT team—they’re cybersecurity defenders who manage vulnerabilities, coordinate patches, and publish security advisories for Siemens products, solutions, and industrial services—and through its industrial cybersecurity offerings.

"Siemens continues to promote secure configuration practices and coordination across the broader industrial automation ecosystem to help prevent misconfigurations and support the safe, resilient operation of critical infrastructure."

About the Author

Scott Achelpohl

Head of Content

I've come to Smart Industry after stints in business-to-business journalism covering U.S. trucking and transportation for FleetOwner, a sister website and magazine of SI’s at Endeavor Business Media, and branches of the U.S. military for Navy League of the United States. I'm a graduate of the University of Kansas and the William Allen White School of Journalism with many years of media experience inside and outside B2B journalism. I'm a wordsmith by nature, and I edit Smart Industry and report and write all kinds of news and interactive media on the digital transformation of manufacturing.

Sign up for our eNewsletters
Get the latest news and updates