A joint NSA-led advisory says threat actors are using internet scanning and AI-assisted scripts disguised as monitoring tools to target inadequately protected Siemens S7 programmable logic controllers in U.S. critical-infrastructure environments.
Key takeaways
- The August 19 advisory describes active reconnaissance and capability development against U.S.-based Siemens S7 PLC installations, rather than a newly disclosed Siemens zero-day vulnerability.
- The agencies say actors use internet scanning services to locate exposed or poorly segmented controllers, then use AI-assisted scripts that imitate legitimate OT monitoring tools.
- Immediate priorities are asset inventory, removal of direct internet exposure, patching, stronger PLC and remote-access controls, and monitoring of S7comm traffic.
- The advisory focuses on Siemens S7 PLCs but states that PLC-targeting activity is broader, making it relevant to OT environments with other controller brands as well.
Joint advisory frames Siemens S7 exposure as an active OT threat
The National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy and Environmental Protection Agency issued a joint Cybersecurity Advisory on August 19, 2026, warning that threat actors are actively conducting reconnaissance and capability development against U.S.-based Siemens S7 Series programmable logic controller installations.
The advisory covers S7-200, S7-300, S7-400, S7-1200 and S7-1500 families, including S7-1500 F-series safety controllers. It identifies critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities as the U.S. sectors most targeted by the observed activity.
Importantly, the agencies describe a threat campaign and a set of defensive priorities, not a single newly announced product flaw. The report does not publicly attribute the activity to a named actor, identify a confirmed affected organization, or report a specific successful disruption. Its central finding is that inadequately protected PLCs are being located and assessed for potential access and future operational impact.
Internet exposure and weak segmentation are central risk factors
According to the advisory, actors are using internet scanning services to identify Siemens S7 controllers that are directly reachable from the internet, operating outdated software, or insufficiently separated from untrusted networks. The agencies warn that exposure can allow exploitation of known vulnerabilities, misconfigurations or weak authentication rather than requiring a new undisclosed vulnerability.
The reported tooling combines AI-assisted script development with publicly available industrial automation libraries, including snap7.dll and python-snap7. The scripts are designed to resemble legitimate OT monitoring software and can communicate with Siemens controllers over the S7comm protocol. The advisory says this can enable read and write access to PLC memory, configuration data and ladder-logic programs.
For plant operators, the concern is not limited to a controller’s public IP address. A PLC may be indirectly exposed through permissive firewall rules, unmanaged remote-support connections, vendor pathways, engineering workstations, cellular routers, or unauthorized routing between corporate and industrial networks. Facilities should validate the complete remote-access path rather than relying on an assumption that the control network is isolated.
Potential consequences extend from process disruption to safety risk
The agencies assess that the observed activity is likely intended to build persistent knowledge of targeted environments and refine capabilities that could later be used to cause operational effects. Unauthorized read access may reveal process configurations, control strategies and facility information; unauthorized writes could create more direct process risk.
Potential impacts identified in the advisory include disrupted industrial processes, product-quality and throughput problems, equipment damage, extended downtime, loss of sensitive operational information, compliance consequences and cascading effects across connected operations. It also notes that manipulation of safety interlocks, emergency shutdown systems or process parameters could create safety incidents.
These outcomes are contingent on the architecture and protections of a particular environment. They nonetheless make change control, controller configuration protection and independent validation of logic changes practical priorities for operations, engineering and cybersecurity teams.
What installers, integrators and asset owners should check first
The agencies recommend an immediate inventory of Siemens S7 assets, including firmware versions, controller location, exposure to untrusted networks and engineering workstations with TIA Portal, STEP 7 or other S7 programming access. Asset owners should compare controller firmware and projects with approved backups or gold copies before making changes.
Organizations should apply applicable Siemens security patches after appropriate testing and prioritize internet-facing or DMZ-resident controllers. They should audit perimeter rules for S7comm on TCP port 102, block that port at the perimeter, remove direct PLC internet access and verify OT/IT segmentation. Where remote operations are necessary, access should be limited to approved engineering systems, protected by strong authentication and controlled through a defined remote-access design.
The advisory also calls for PLC password protection, appropriately configured read/write protection levels, changes to default SNMP community strings, application allowlisting on engineering workstations and multifactor authentication for remote OT access. Integrators and managed service providers should be included in the review because their access arrangements can create exposure that is not visible to the asset owner.
Monitoring should focus on engineering activity and S7comm anomalies
Detection teams should establish a baseline for legitimate engineering and controller communications, then investigate deviations. The advisory highlights S7comm connections from non-engineering workstations, unusual data-block reads, write operations outside approved maintenance windows, repeated connection attempts and sequential scanning activity on TCP port 102.
Other signals include unexpected TIA Portal or STEP 7 sessions, configuration changes without associated work orders, unauthorized monitoring-tool installations, and Python processes importing snap7.dll on engineering workstations. ICS-aware monitoring can help correlate those events with plant change records and approved vendor work.
Although this alert is Siemens-specific, the authoring agencies state that the broader PLC-targeting problem extends beyond one manufacturer. Facilities should use the Siemens review as a trigger to assess every internet-connected or remotely accessible OT device, particularly controllers that support remote programming or process-critical functions.
Sources
- Defending Against an Active Threat to Siemens S7 Series PLCs — National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, Environmental Protection Agency
- NSA and Others Release Report on Active Threats of Programmable Logic Controllers — National Security Agency
