US Agencies Warn of Active Cyber Threat Targeting Siemens Industrial Control Systems
Key Takeaways
- •Five U.S. federal agencies, including the NSA, FBI, and CISA, identified an active threat against Siemens S7 Series programmable logic controllers used in critical infrastructure sectors such as water, energy, and manufacturing.
- •Attackers are reportedly using artificial intelligence to develop exploitation tools, significantly reducing the time and expertise required to compromise industrial control systems.
- •The advisory warned that successful intrusions could halt critical operations, damage equipment, create safety hazards, and trigger cascading failures across interconnected systems.
- •The alert follows a surge in attacks on local water systems, including at least 30 incidents reported in Minnesota in late July, though federal officials have not formally attributed them to Iran.
- •Siemens stated it has detected no increased attack activity or unknown vulnerabilities in its industrial control products and is coordinating with CISA while providing customer updates through its ProductCERT team.

U.S. federal agencies are warning that hackers are actively targeting industrial control systems used at water plants, factories, energy facilities and other critical infrastructure across the country.
The National Security Agency, FBI, Department of Energy, Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency said Wednesday that an "active threat" is targeting Siemens S7 Series programmable logic controllers. The devices are used to monitor and control industrial equipment across sectors including manufacturing, energy, water and wastewater, chemicals, and food and agriculture. Siemens controllers have been at the center of major industrial cyber incidents before: the Stuxnet malware uncovered in 2010 manipulated Siemens S7 PLCs to physically damage centrifuges at Iran's Natanz nuclear site, a case still cited as a landmark demonstration that code can destroy equipment.
According to the advisory, a successful attack could disrupt critical operations, force facilities offline, damage equipment and create safety hazards. Officials also warned that breaches could trigger cascading disruptions across interconnected systems.
The government said hackers are increasingly using artificial intelligence to make such attacks easier, dramatically reducing the expertise and time needed to develop tools capable of exploiting industrial systems. According to the advisory, attackers are scanning the internet for exposed or poorly protected Siemens controllers and using AI-generated tools to help gain access to them.
Federal agencies said the activity appears aimed in part at studying targeted systems and developing the ability to disrupt operations in the future. Such attacks could affect production, public services and supply chains, while also causing equipment damage or prolonged downtime. Officials also cautioned that some operators may not realize their systems are exposed, particularly when outside vendors have remote access to industrial equipment.
The warning comes amid a recent wave of cyberattacks against local water systems that cybersecurity experts suspect may have links to Iran, though federal officials have not formally attributed those incidents to Tehran. CISA warned on July 30 of a significant increase in attacks targeting programmable logic controllers. Days earlier, the agency said Iranian-affiliated hackers had been exploiting industrial equipment made by Siemens, Rockwell Automation and Schneider Electric.
Concerns intensified after Minnesota became the first state to report a wave of at least 30 cyber incidents involving local water systems on July 26 and July 27. Federal officials have stopped short of blaming Iran for those attacks. President Donald Trump said on July 31 that he did not believe Tehran was responsible and instead criticized Minnesota over the incidents. The water sector has faced remote intrusions before, including a 2021 episode in Oldsmar, Florida, in which an intruder remotely accessed a treatment plant and attempted to raise a chemical setting before an operator reversed the change.
The latest warning underscores the vulnerability of operational technology — systems that control physical equipment rather than simply store corporate data. Unlike conventional cyberattacks focused on stealing information, attacks on industrial control systems can have direct physical and economic consequences, potentially interrupting utilities, shutting down production or damaging costly equipment. The potential fallout can extend beyond an individual facility, affecting businesses and services that rely on interconnected industrial systems.
Siemens said Thursday that it had not detected an increased level of attacks or any previously unknown vulnerabilities affecting its industrial control systems products. The company told FOX Business that it is aware of the alert and is coordinating with CISA.
"Siemens will provide updates around this issue to potentially affected customers through our ProductCERT team," a company spokesperson said. "At this point in time, we have not identified increased attack levels or unknown vulnerabilities in Siemens ICS products."
For facility operators, the officials' caution about unnoticed exposure — particularly through outside vendors with remote access — points to the immediate practical question of establishing who can reach their controllers. Siemens has said follow-up information will flow through its ProductCERT team, and CISA has been issuing rolling warnings on programmable logic controller targeting, giving operators two official channels to monitor for further developments.
Reuters contributed to this report.