FBI: Hackers Are Targeting US Industrial and Water Systems With Help of AI The FBI, along with the NSA and other federal agencies, warned on Wednesday that hackers are using AI to create exploitation scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) in US industrial and water systems. The AI-assisted attacks reduce the technical expertise and time needed to develop malicious tools, posing an active threat that could disrupt critical processes, cause safety incidents, or damage equipment. The alert urges operators to patch systems and ensure PLCs are not accessible from the internet. Hackers targeting US critical infrastructure, including energy and water providers, are using AI to help them break into vulnerable industrial IT systems, according to the FBI. On Wednesday, the FBI joined with several federal agencies, including the NSA, to warn https://www.ic3.gov/CSA/2026/260819.pdf the public about the “active threat,” which has been targeting Siemens-developed industrial systems connected to the internet. The FBI is raising alarm bells, noting the hackers have been using AI to create “exploitation scripts https://www.pcmag.com/encyclopedia/term/script ” or malicious instructions written in computer code to help them hijack access to the internet-exposed industrial systems. The AI use has been able to do so by harnessing publicly available information about the Siemens systems to lead to “initial access, credential access, denial of service, and other objectives,’ the alert says. “Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS industrial control system exploitation scripts and malicious tools,” the FBI added. “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures.” For example, the AI-assisted scripting can create custom tools that pretend to mimic legitimate monitoring software on the industrial computers. The alert doesn't identify the AI used. But the threat underscores a growing trend of hackers, including state-sponsored groups, using AI programs to amplify their operations. This past summer, suspected Chinese hackers used /ai/166678/chinese-hackers-created-a-near-autonomous-attack-using-open-source-ai open-source AI to create a “near-autonomous attack” capable of cracking 85 government accounts reportedly in Taiwan. In this case, the hackers have been targeting programmable logic controllers https://www.pcmag.com/encyclopedia/term/plc , or specialized computers used to control industrial systems. The FBI’s alert flagged PLCs under the Siemens S7 Series used in the US. The danger covers a wide range of industries including manufacturing, food and agriculture and other commercial facilities, in addition to the energy and water sector. “This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the alert says. The warning seems related to a string of recent hacks that’ve been targeting /security/166499/fbi-hackers-targeted-water-utility-providers-in-at-least-7-states water utility providers in at least 12 https://www.csis.org/analysis/mapping-iranian-cyberattacks-us-water-systems US states. Last month, the FBI warned the water utility hacks involved internet-exposed PLCs under the MicroLogix 1100 and 1400 series from Rockwell Automation/Allen-Bradley. The AI use may explain how the hackers have been able to quickly scale their efforts. Privately, the US suspects Iranian state-sponsored groups are likely behind the water utility hacks, according https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html to The New York Times . In the meantime, the FBI's alert goes on to warn the hackers have been targeting Siemens PLCs set with "unconfigured default or minimally configured authentication." In response, the agency is urging the industry to apply patches and "ensure PLCs are NOT accessible from the Internet," among a host of other mitigation measures.