# NSA and CISA Warn Hackers Are Using AI to Scan Siemens Plant Controllers

> Source: <https://startupfortune.com/nsa-and-cisa-warn-hackers-are-using-ai-to-scan-siemens-plant-controllers/>
> Published: 2026-08-21 01:21:15+00:00

*Five federal agencies say attackers are using AI-written Python scripts to hunt exposed Siemens plant controllers, and the warning is aimed at operators who still have industrial gear sitting too close to the open internet.*

The NSA, CISA, the FBI, the Department of Energy, and the EPA issued the joint advisory on August 19. It warns that threat actors are actively scanning for internet-exposed Siemens S7 Series programmable logic controllers, the small industrial computers that run pumps, valves, and production lines across critical manufacturing, energy, water and wastewater, chemical processing, food and agriculture facilities. The advisory, identified as AA26-231A in multiple reports on the warning, says attackers are using AI-generated Python exploitation scripts built with open-source snap7.dll and python-snap7 libraries to reach these devices through the S7comm protocol.

## How the Attack Works

Here's how it works. Attackers use internet scanning platforms such as Censys and ZoomEye to find S7 PLCs sitting exposed on the open internet, often with outdated software or weak protection. They then use AI tools and public information to speed up the creation of scripts that can talk to the controllers over TCP port 102. According to Reuters, the agencies said AI is reducing the technical skill and time needed to build exploits against the systems. That's the change plant operators can't shrug off.

The scripts are built to mimic operational technology monitoring software. Once they reach a poorly protected controller, they can give attackers access to PLC memory, configuration data, and ladder logic programs, the code that tells a controller when to open a valve, start a motor, stop a process. The Register reported that the advisory describes read and write access through S7comm, which is why this is more than a scanning problem. Reading a plant's logic is reconnaissance. Writing to it is where physical disruption starts.

The advisory doesn't name a specific hacking group, and it doesn't claim every exposed Siemens device has been damaged. That distinction matters. The warning is about active targeting and capability building against equipment that sits inside real plants, not a tabletop risk exercise. If you run a facility and your PLCs are reachable from the internet, the agencies are telling you the hard part may already have been made easier for the attacker.

[Federal agencies now have three days to patch the most dangerous vulnerabilities and AI acceleration is the explicit reason](https://startupfortune.com/federal-agencies-now-have-three-days-to-patch-the-most-dangerous-vulnerabilities-and-ai-acceleration-is-the-explicit-reason/)

CISA's new Binding Operational Directive BOD 26-04 compresses federal vulnerability remediation windows to 72 hours for the highest-risk flaws and becomes the first federal cybersecurity mandate to formally cite AI-driven threat acceleration as its core rationale. The directive's tiered risk matrix, anchored to the KEV catalog, creates immediate... - [federal agencies three days patch vulnerabilities](https://startupfortune.com/federal-agencies-now-have-three-days-to-patch-the-most-dangerous-vulnerabilities-and-ai-acceleration-is-the-explicit-reason/) - [AI acceleration exploit speed policy directive](https://startupfortune.com/federal-agencies-now-have-three-days-to-patch-the-most-dangerous-vulnerabilities-and-ai-acceleration-is-the-explicit-reason/)

The affected list is broad: S7-200 controllers, S7-300 models including the 314, 315, and 317, the S7-400 line, S7-1200 CPUs from 1211C through 1217C, and S7-1500 devices, including F-series safety controllers. That's not a niche corner of factory automation. Siemens S7 controllers are workhorse equipment, and many sites keep industrial hardware in service for years because replacing a working control system is expensive and disruptive - schedules don't bend easily around it.

## The Fix Starts With Exposure

Here's the thing: this advisory is not asking operators to buy mystery software and hope for the best. The first fix is plain. Take Siemens S7 PLCs off the public internet. If that can't happen immediately, block S7comm traffic on TCP port 102 at the network edge and put operational technology networks behind a proper demilitarized zone rather than letting them sit directly beside corporate IT systems.

For higher-risk plants, the agencies recommend unidirectional gateways, hardware that lets data leave the plant network but blocks traffic from coming back in. They also tell operators to inventory S7 controllers, check firmware, apply patches through the Siemens process, tighten access from engineering workstations, and monitor for behavior that doesn't fit normal operations. A connection from the wrong workstation, repeated port 102 scans, odd data block access, or Snap7 use outside approved machines should not be treated as noise.

None of this is abstract for water utilities, food processors, and chemical plants. These sectors often run older gear and thin security teams - and production schedules that punish any downtime. The budget problem is real, but it doesn't change the threat. Frankly, the old assumption that industrial networks are too obscure to attract easy attacks has taken another hit. AI did not invent the Siemens S7 problem. It made the path shorter.

The useful part of the August 19 warning is its specificity. It names the vendor, the controller family, the libraries, the protocol, the port, and the scanning tools. That gives operators something concrete to act on, which is better than another broad call to stay alert. If a plant still has an S7 controller visible from the internet after this advisory, the exposure is no longer an accident. It's a decision.

**Also read:** [Micro1 Rockets From $7 Million to $300 Million in Revenue in a Single Year](https://startupfortune.com/micro1-rockets-from-7-million-to-300-million-in-revenue-in-a-single-year/) • [Xpeng Beats Tesla's Margins While Racing to Build Robots and Robotaxis](https://startupfortune.com/xpeng-beats-teslas-margins-while-racing-to-build-robots-and-robotaxis/) • [Americans Moving to Canada: The Financial Decisions That Cannot Wait Until After the Move](https://startupfortune.com/americans-moving-to-canada-the-financial-decisions-that-cannot-wait-until-after-the-move/)
