{"slug": "ai-fueled-attacks-pose-active-threat-to-water-other-sectors-u-s-agencies-warn", "title": "AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn", "summary": "U.S. agencies including the National Security Agency, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department, and Environmental Protection Agency warned Wednesday that hackers are using AI-generated exploitation scripts to target Siemens S7 Series programmable logic controllers (PLCs) in water, food, energy, chemical, manufacturing, and commercial facilities, calling the attacks an 'active threat.' The advisory marks the first time CISA has noted AI scripts targeting operational technology, according to former CISA official Michael Garcia, now vice president at Monument Policy Advocacy.", "body_md": "# AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn\n\nHackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday.\n\nIt’s the latest government warning about [attacks on critical infrastructure](https://cyberscoop.com/trump-blames-minnesota-water-cyberattacks-iran/) as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems— but doesn’t mention in Wednesday’s alert.\n\nThe National Security Agency didn’t immediately respond to a request for comment about who was behind the attacks on the PLCs, which are used to control manufacturing processes.\n\nThe agencies said the attacks were an “active threat,” rather than a theoretical one. The attacks could disrupt critical industrial processes, cause safety incidents or lead to the compromise of sensitive data.\n\n[Wednesday’s alert](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery) from the NSA, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department and Environmental Protection Agency makes special note of the hackers using AI-generated exploitation scripts in the attacks.\n\n“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the alert states. “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”\n\nA former top CISA official, Michael Garcia, thought that it was a first for the agency in one of its cybersecurity advisories (CSAs) about operational technology (OT).\n\n“It is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems,” Garcia, now vice president of the cybersecurity practice at Monument Policy Advocacy, [said on LinkedIn](https://www.linkedin.com/feed/update/urn:li:activity:7495873382983340033/). But the advisory doesn’t recommend using AI in response, instead focusing on well-known, traditional defensive measures, he added.\n\nFrenos, an OT penetration testing company, found another element of the alert troubling: The method by which the attackers could use the approach beyond Siemens-made PLCs.\n\n“Siemens S7 is the subject here, but the exposure pattern is not brand specific,” Brian Proctor, CEO of the company, said in an email. “An adversary who has mapped your data blocks understands your process. They know what normal looks like, which means they know what an operator would fail to notice.”\n\nThe AI-generated scripts are disguised as legitimate monitoring tools, the advisory said of the hackers behind them.\n\n“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the advisory reads.\n\nSiemens did not immediately respond to a request for comment.", "url": "https://wpnews.pro/news/ai-fueled-attacks-pose-active-threat-to-water-other-sectors-u-s-agencies-warn", "canonical_source": "https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/", "published_at": "2026-08-19 18:45:53+00:00", "updated_at": "2026-08-19 18:55:25.008145+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["National Security Agency", "Cybersecurity and Infrastructure Security Agency", "FBI", "Energy Department", "Environmental Protection Agency", "Siemens", "Michael Garcia", "Monument Policy Advocacy"], "alternates": {"html": "https://wpnews.pro/news/ai-fueled-attacks-pose-active-threat-to-water-other-sectors-u-s-agencies-warn", "markdown": "https://wpnews.pro/news/ai-fueled-attacks-pose-active-threat-to-water-other-sectors-u-s-agencies-warn.md", "text": "https://wpnews.pro/news/ai-fueled-attacks-pose-active-threat-to-water-other-sectors-u-s-agencies-warn.txt", "jsonld": "https://wpnews.pro/news/ai-fueled-attacks-pose-active-threat-to-water-other-sectors-u-s-agencies-warn.jsonld"}}