Hacking

AI-Generated PLC Attacks Target Critical Infrastructure

Published  ·  6 min read

AI-Generated PLC Attacks

The U.S. government just issued a warning that should make anyone in critical infrastructure sit up and take notice. An active threat is targeting industrial control systems across the country, and the attackers are using AI to do it.

The targets are Siemens S7 Series Programmable Logic Controllers, the devices that run power plants, water treatment facilities, and manufacturing lines. Attackers are using AI to generate exploit scripts that look like legitimate monitoring tools. But they're really for reconnaissance and finding ways in.

This isn't just one agency sounding the alarm. The NSA, CISA, the FBI, the Department of Energy, and the EPA all signed on to the advisory. That tells you how seriously they're taking this.

Let's take a more look into what's happening and what you need to be aware of.

What's Going on?

The attacks are made by attackers who use AI to generate scripts to attack Siemens S7 PLCs. These are the brains of industrial control systems. The attackers are scanning the internet for exposed devices, then using AI-written code to try and break in.

The Targets:

  • Critical Manufacturing
  • Energy
  • Water and Wastewater Systems
  • Chemical
  • Food and Agriculture
  • Commercial Facilities

The Siemens Models Being Targeted:

  • S7-200 Series
  • S7-300 Series (including 314, 315, 317)
  • S7-400 Series
  • S7-1200 Series (1211C, 1212C, 1214C, 1215C, 1217C)
  • S7-1500 Series (including F-series safety controllers)

How the Attack Works

Step 1: Reconnaissance

Attackers use internet scanning services like Censys and ZoomEye. They target vulnerable PLCs with out-of-date software versions. They're pretty much searching for open doors.

Step 2: AI-Generated Scripts

The attackers use AI technology to generate scripts for exploitation using the publicly available data about the Siemens S7 Series Programmable Logic Controllers.

This is aimed at creating code that will:

  • Provide initial access
  • Steal credentials
  • Create denial of service
  • Other malicious purposes

Step 3: Custom Tools

The attackers rely on custom scripts written in Python. The scripts leverage libraries which are publicly accessible, for example, snap7 or python-snap7. The scripts emulate legitimate monitoring tools. But they're actually providing read/write access to PLC memory and configuration data.

The Role of AI in ICS Attacks

The use of AI to generate exploitation scripts is a game-changer.

What's Changing:

  • Technical barriers are lowering
  • Less expertise is required
  • Development time is shrinking

The Agencies' Warning:

"The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations."

The Taiwan Attack

The AI-generated PLC attacks aren't the only story. Last week, Israeli cybersecurity company Dream detailed a near-autonomous attack on Taiwan's government.

When It Happened:

July 1 to 4, 2026, across 12 attack waves.

How It Worked:

The attackers used an AI-powered framework built on Hermes and OpenClaw agents. They used eight subagents simultaneously for carrying out each part of the attack.

The Sub-Agents:

  • A – SSO exploitation and credential attacks
  • B – JWT bypass testing and CAPTCHA brute-force
  • C – Reconnaissance across government portals
  • D – API scanning and admin panel bypass
  • E – CVE research and vulnerability chain testing
  • F – Supply chain target assessment
  • I – Password spraying with CAPTCHA bypass
  • Q – Deep API endpoint exploitation

What They Achieved:

In about four days, the attackers produced:

  • 1,395 files
  • 85 cracked credentials
  • Thousands of exfiltrated personnel records
  • A persistent foothold inside state infrastructure

The Data Stolen:

  • 2,564 personnel records
  • A database of all department system users
  • Seven SSO client secrets
  • Six internal database credentials (MSSQL, Oracle, Sybase)
  • Internal network IP ranges

They Didn't Stop There:

The attackers expanded to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies. They scanned them all in parallel for weaknesses.

The Scary Part:

The framework has a learning engine. It looks up vulnerability databases, GitHub repositories, and security research. It adapts to find techniques that work on the target infrastructure.

The Bottom Line:

"In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure," Dream said.

"It spells out one thing loudly – the cost of running a competent attack has collapsed, but the cost of defending against one has not."

What You Should Do

If you work in critical infrastructure, here's what you need to do right now:

1. Update Firmware

Make sure all Siemens S7 Series PLCs are running the latest versions. Outdated software is a primary target.

2. Isolate from the Internet

PLCs should not be exposed to the internet. Use network segmentation to limit access.

3. Implement Strong Access Controls

Use strong authentication. Remove default credentials.

4. Utilize security tools

Watch out for any malicious actions within the ICS system environment. Utilize security tools that are suitable for the ICS system.

5. Be Informed

Stay informed about recent advisory notes published by CISA, NSA, and other agencies.

The Bottom Line

AI-generated PLC attacks are a new reality. Attackers are using AI to create exploitation scripts faster and more efficiently. The U.S. government is warning that this is an active threat.

What You Need to Know:

  • Active threat targeting critical infrastructure
  • Uses AI-generated exploit scripts
  • Targets Siemens S7 Series PLCs
  • Multi-agent AI attack hit Taiwan
  • The cost of attack is dropping; defense is not

What You Need to Do:

  • Update firmware
  • Isolate PLCs from the internet
  • Implement strong access controls
  • Deploy security tooling
  • Stay informed

FAQ Section

What are AI-generated PLC attacks?

These are attacks targeting industrial control systems where threat actors use AI to generate exploitation scripts. The attacks are targeting Siemens S7 Series PLCs in critical infrastructure.

What is the target of these attacks?

The attacks target Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities.

What happened in Taiwan?

An almost autonomous AI attack was conducted against the government of Taiwan from July 1-4, 2026, through the use of Hermes and OpenClaw agents to launch eight sub-agents at once.

How many data were stolen in the attack against Taiwan?

In the attack against Taiwan, the hackers managed to steal 2,564 user profiles, a database that includes details about all department system users, seven SSO client secrets, six database logins, and IP addresses of the internal network.

What measures should firms take?

Firmware patching, isolation of PLCs from the internet, access controls, and deployment of security tooling for monitoring ICS.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067