U.S. agencies including NSA, CISA, FBI, DOE, and EPA warned that threat actors are actively targeting Siemens S7 Series PLCs used across critical infrastructure, including water and wastewater, energy, chemical, food and agriculture, manufacturing, commercial facilities, and potentially the Defense Industrial Base. The advisory says attackers are focusing on internet-exposed controllers with outdated software, weak authentication, or known high-severity vulnerabilities, using AI-generated Python scripts disguised as legitimate monitoring tools and leveraging components such as snap7.dll and python-snap7 to communicate with and exploit devices.
Officials said the activity appears aimed at persistent reconnaissance and capability development that could support future disruption of industrial operations. A successful compromise could lead to process outages, safety incidents, equipment damage, sensitive data exposure, compliance issues, and cascading effects across connected environments. Agencies urged operators to inventory Siemens S7 assets, remove direct internet exposure, apply updates and patches, strengthen access controls, and increase monitoring for suspicious activity on OT networks.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A July federal warning said Iran-affiliated hackers were targeting PLCs from Siemens, Schneider Electric, Rockwell Automation, and Allen-Bradley. Officials were alarmed after dozens of water utilities in at least 12 U.S. states reported cyber intrusions allegedly involving Iranian actors targeting PLCs.
In July, hackers targeted more than 30 Minnesota water utilities, causing equipment malfunctions. Some utilities temporarily switched to manual operations as a result of the attacks.
Earlier in April, U.S. agencies warned that Iranian-linked hackers were targeting internet-exposed Rockwell Automation and Allen-Bradley PLCs. The activity reportedly caused disruptions and financial losses across multiple critical infrastructure sectors.
The NSA, CISA, FBI, Department of Energy, and EPA issued a joint advisory warning that threat actors are actively targeting Siemens S7 Series PLCs used in U.S. critical infrastructure. The advisory said attackers are using AI-generated Python exploitation scripts disguised as legitimate OT monitoring tools, along with known vulnerability exploitation and internet scanning, to access exposed or weakly protected devices.
After the Minnesota incidents, CISA warned of an increase in attacks against internet-exposed PLCs used by water and wastewater utilities. The warning highlighted growing risk to exposed operational technology in that sector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
21 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecysecurity.news
Open sourcetomshardware.com
Open sourcewaterisac.org
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceteiss.co.uk
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.