
The latest attacks against critical infrastructure are giving cybersecurity teams a problem they have been warning about for years, but with a new layer of speed. Attackers are now using AI to develop and modify tools designed to target the programmable controllers that run water systems, energy facilities, and other industrial operations.
On August 19, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, Department of Energy and Environmental Protection Agency, warned of an active campaign targeting Siemens S7 Series programmable logic controllers. The agencies said attackers were using AI-generated exploitation scripts and internet scanning services to identify exposed or poorly protected systems.
AI Is Now Part of the Attack Process
The activity described by the agencies shows that threat actors are using AI to speed up parts of the attack process.
According to the advisory, attackers are combining publicly available information about Siemens PLCs with AI-assisted scripting and open-source libraries such as Snap7 and Python-Snap7. They have created tools that can resemble legitimate operational technology monitoring software while allowing them to read and write PLC memory, configuration data, and ladder logic programs.
The agencies said the activity appears focused on reconnaissance, capability development, and positioning for possible future disruptive operations, however, they did not attribute the campaign to a specific threat actor or country.
Water and Energy Systems Are Among the Targets
The threat extends beyond Siemens equipment. CISA said PLC targeting activity is broader than the specific Siemens campaign and urged operators of all PLCs to apply appropriate security measures.
The sectors most affected by the activity include energy, water and wastewater, critical manufacturing, chemical facilities, food and agriculture, and commercial facilities. And a successful compromise could cause industrial disruption, equipment damage, downtime, or safety incidents.
This warning comes after a separate wave of attacks against U.S. water and wastewater systems. CISA said in July that it was observing malicious activity targeting PLCs used by water utilities, while its latest exposure guidance says more than 100 internet-exposed water and wastewater systems were targeted during July.
The Playbook Problem
The challenge for defenders is arriving as AI makes parts of the attack process faster and easier to repeat. CISA’s latest advisory recommends that operators inventory their PLCs, apply security patches, remove them from direct internet exposure, strengthen access controls, and monitor industrial networks for suspicious activity.
CISA also disclosed in July that it had to build an incident response playbook while dealing with a separate cloud security leak involving exposed credentials. While the incident was unrelated to the infrastructure attacks, the admission showed that even a federal cybersecurity agency can encounter situations where existing response procedures do not fully cover a new type of incident.
And this gap matters as AI becomes more deeply involved in cyberattacks. Security teams now have to account for attackers who can use AI to develop exploitation tools faster, adapt them to different systems, and automate parts of reconnaissance and intrusion.
For operators of water plants, power facilities, and other industrial systems, the immediate lesson from CISA is that internet exposure, weak access controls, and outdated industrial equipment can give attackers an opening, while AI can make it easier for them to take advantage of that opening.
