U.S. Agencies Warn of Hackers Actively Attacking Siemens S7 PLCs in Critical Facilities

The NSA, CISA, FBI, Department of Energy, and EPA issued a joint cybersecurity advisory on August 19 warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) across America’s critical infrastructure.

The agencies describe this as a live, ongoing threat rather than a theoretical risk, with attackers using AI-generated exploitation scripts disguised as legitimate monitoring tools to probe and manipulate Internet-exposed devices.

According to the advisory, threat actors are leveraging Internet scanning services such as Censys and ZoomEye to locate Siemens S7 PLCs that are exposed to the public Internet or insufficiently segmented from corporate networks.

Once a vulnerable device is found, attackers use AI-assisted development to rapidly generate and refine exploitation code, dramatically cutting the technical expertise and time historically needed to build working industrial control system exploits.

Hackers Attacking Siemens S7 PLCs

The tools rely on open-source automation libraries, specifically snap7.dll and python-snap7, to gain read and write access to PLC memory, configuration data, and ladder logic programs through the S7comm protocol, all while masquerading as routine operational technology monitoring software to avoid detection.

Every major S7 product line is in the crosshairs, including the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series, along with the F-series safety controllers.

Agencies noted that attackers are also taking advantage of exposed devices left with default or minimally configured credentials, making initial access even easier where basic authentication hygiene has been skipped.

Investigators assess that the current wave of activity looks like persistent reconnaissance and capability development rather than immediate sabotage. Threat actors appear to be testing exploitation techniques against specific PLC models and using read access to map out target environments, effectively pre-positioning for future write operations that could cause real operational disruption.

The sectors most affected include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities, with the Defense Industrial Base also flagged as a potential target given its reliance on Siemens controllers.

The timing lines up with a string of recent cyber incidents at U.S. water utilities in Georgia, Minnesota, and Michigan, underscoring how operational technology environments serving essential services remain a persistent target for adversaries seeking leverage over physical infrastructure.

Potential consequences outlined in the advisory range from disrupted industrial processes and safety incidents involving manipulated interlocks or emergency shutdown systems, to equipment damage, extended downtime, and cascading effects across interconnected supply chains.

The authoring agencies are urging every owner and operator running Siemens S7 PLCs, and PLCs more broadly, to move quickly on several fronts.

That starts with a full inventory of every S7 device on the network, followed by applying the latest firmware and security patches, particularly for any controller sitting in a DMZ or reachable from outside networks.

Operators are also told to block TCP port 102 at perimeter firewalls, verify that no PLC is directly accessible from the Internet, and tighten access controls by restricting TIA Portal and STEP 7 engineering access to authorized workstations only.

Continuous monitoring is equally critical. The advisory recommends deploying ICS-aware intrusion detection, watching for anomalous S7comm traffic, unauthorized write operations, off-hours connections, and any Python processes importing the snap7.dll library on engineering systems.

Organizations working with third-party integrators or managed service providers are advised to share the advisory directly with those vendors, since remote access arrangements can create blind spots that leave asset owners unaware their systems are already exposed.

U.S. organizations that detect suspicious activity are encouraged to report it to CISA or the FBI’s Internet Crime Complaint Center, while entities under DOE reporting obligations should follow their existing incident notification procedures.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post U.S. Agencies Warn of Hackers Actively Attacking Siemens S7 PLCs in Critical Facilities appeared first on Cyber Security News.