NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

Federal agencies said there is an “active threat” targeting critical infrastructure organizations using AI-generated exploit scripts, in what they called an “evolution” in capabilities.
Organizations were urged to treat Wednesday’s advisory “with urgency” and initiate response efforts centered around programmable logic controllers (PLCs) — tools used by the energy, water and agricultural industries to control pumps and monitor processes.
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.
“This is not a theoretical risk — it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory said.
Unidentified threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools, it adds. The hackers are using internet scanning platforms to find PLCs exposed to the internet.
Federal agencies said in July that Iran-affiliated hackers were targeting PLCs made by several different companies alongside Siemens – including Schneider Electric, Rockwell Automation and Allen-Bradley.
“The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape,” Wednesday’s advisory said.
Operators were urged to isolate PLCs from the internet, install all patches and enable security tooling to monitor threat activity.
Automated scripts
Hackers behind the campaign are using artificial intelligence to generate exploitation scripts that give them access to credentials and other pathways for damage.
The agencies called the use of AI to generate exploitation scripts “an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working [Industrial Control System] exploitation scripts and malicious tools.”
AI is also helping attackers adapt quickly to defensive measures, in some cases enabling them to create custom tools designed to look like legitimate operational technology monitoring solutions.
Several of the agencies listed on the advisory directed questions to the White House and NSA, which did not respond by time of publication. Siemens did not respond to requests for comment.
The advisory does not attribute the activity, only writing that the attacks are “likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure.”
In addition to critical infrastructure managing the country’s water, power and manufacturing, Siemens PLCs are used heavily in the defense industry.
Government officials were alarmed two weeks ago when dozens of water utilities across at least 12 states reported cyber intrusions allegedly involving Iranian actors targeting PLCs. Several different measures were introduced to address the issue but Wednesday’s advisory appears to expand the campaign beyond water and wastewater facilities.
Industrial technology expert Brian Proctor said the introduction of AI compressed the distance between a published vulnerability and a working script in the hands of someone who previously could not have written it themselves.
“The barrier that used to be expertise is now time, and time is getting shorter,” he said, adding that the activity described in the advisory “is the first half of an effects operation, and the second half is cheap once the first half is done.”
Proctor noted that the advisory acknowledges that most end users of PLCs do not know they are exposed because the exposure was introduced by a third-party vendor.
Organizations, he said, need to plan for what happens when they lose control of a PLC.
“Because that is where this ends if the reconnaissance is allowed to mature. Not a data breach,” said Proctor, who is CEO of operational technology pentesting company Frenos. “Loss of view, loss of control, and a physical process running in a state nobody in the control room can see.”
References in this story
- Defending Against an Active Threat to Siemens S7 Series PLCs | CISA www.cisa.gov This advisory warns of threat actors targeting Siemens S7 Series programmable logic controllers (PLCs) and includes mitigations to be understood and applied within the broader context of ongoing threats to PLCs and…
- Federal agencies broaden alert on Iran-linked OT attacks therecord.media The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
- Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents therecord.media Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow.
- Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity therecord.media Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.
- Water utilities group partners with DEF CON offshoot for Water Watch Center therecord.media The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



