{"slug": "fbi-warns-that-hackers-are-targeting-siemens-equipment-amid-recent-water-plant", "title": "FBI Warns That Hackers Are Targeting Siemens Equipment Amid Recent Water Plant Breaches", "summary": "The FBI, NSA, and CISA issued a joint advisory warning that hackers are actively targeting Siemens S7 Series programmable logic controllers (PLCs) used in U.S. water plants and other critical infrastructure, using AI-generated Python scripts to gain read and write access while mimicking legitimate monitoring tools. The advisory, released this week, says attackers are exploiting internet-exposed PLCs running outdated software across sectors including manufacturing, energy, water, and chemical, and recommends operators take inventory, patch, and restrict internet access. The warning follows recent attacks on water systems in at least seven states, with Minnesota reporting roughly 36 municipal water systems hit.", "body_md": "Hackers are actively targeting Siemens equipment used in water plants and other critical infrastructure, several U.S. agencies are warning.\n\nThe National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), along with other agencies like the FBI, have issued a [joint cybersecurity advisory](https://media.defense.gov/2026/Aug/18/2003983494/-1/-1/1/CSA_ACTIVE_THREAT_TO_SIEMENS_S7_SERIES_PLCS.PDF) this week detailing an active threat against Siemens S7 Series programmable logic controllers (PLCs).\n\nThese controllers are industrial computers used to operate physical equipment and processes, including pumps and valves at water treatment facilities.\n\n“The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools,” the advisory reads.\n\nAccording to the agencies, the attackers are using internet-scanning services to find Siemens PLCs that are exposed online and are running outdated software or are poorly protected. The sectors being targeted include manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. The agencies warn that a successful attack could disrupt critical industrial processes, create safety risks, damage equipment, cause downtime, or compromise sensitive operational data.\n\nAdditionally, AI seems to be playing a role.\n\nThe advisory says attackers are using AI to cut down on the technical expertise and time needed to develop exploits. Specifically, they are using AI-generated Python scripts to gain read and write access to Siemens PLCs while mimicking legitimate monitoring tools and avoiding detection.\n\nThe warning comes amid a recent wave of cyberattacks against U.S. water systems. In July, the FBI and EPA warned that hackers were targeting internet-connected PLCs at water and wastewater facilities. At the time, water systems in at least [seven states reported](https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions) incidents to the FBI. Months earlier, CISA and other federal agencies had issued a separate warning that [Iranian-affiliated hackers](https://gizmodo.com/pro-iran-hackers-target-critical-u-s-energy-and-water-infrastructure-2000743674) were actively targeting PLCs used in critical infrastructure. Minnesota was hit particularly hard. State officials said roughly [36 municipal water systems](https://gizmodo.com/trump-claims-minnesota-is-behind-cyberattack-on-its-own-water-systems-not-iran-2000793470) were attacked.\n\nPresident Donald Trump, however, downplayed the possibility that Iran was behind the Minnesota attacks and instead blamed the state and Gov. Tim Walz. “We heard in Minnesota there was a cyberattack and they blame it on Iran,” Trump said in a televised cabinet meeting. “I don’t think so. I blame it on Minnesota because they’re grossly incompetent.”\n\nThe latest Siemens advisory adds to mounting warnings from the federal government over the vulnerability of critical infrastructure in the United States. Siemens did not immediately respond to a request for comment.\n\nThe agencies recommend that operators take inventory of Siemens S7 Series PLCs, install critical security patches, make sure the controllers are not accessible from the internet, strengthen access controls, and monitor for suspicious activity.", "url": "https://wpnews.pro/news/fbi-warns-that-hackers-are-targeting-siemens-equipment-amid-recent-water-plant", "canonical_source": "https://gizmodo.com/fbi-warns-that-hackers-are-targeting-siemens-equipment-amid-recent-water-plant-breaches-2000800534", "published_at": "2026-08-19 20:10:36+00:00", "updated_at": "2026-08-19 20:42:55.077240+00:00", "lang": "en", "topics": ["ai-tools", "ai-policy"], "entities": ["FBI", "NSA", "CISA", "Siemens", "Siemens S7 Series PLCs", "Donald Trump", "Tim Walz"], "alternates": {"html": "https://wpnews.pro/news/fbi-warns-that-hackers-are-targeting-siemens-equipment-amid-recent-water-plant", "markdown": "https://wpnews.pro/news/fbi-warns-that-hackers-are-targeting-siemens-equipment-amid-recent-water-plant.md", "text": "https://wpnews.pro/news/fbi-warns-that-hackers-are-targeting-siemens-equipment-amid-recent-water-plant.txt", "jsonld": "https://wpnews.pro/news/fbi-warns-that-hackers-are-targeting-siemens-equipment-amid-recent-water-plant.jsonld"}}