Siemens PLCs Targeted by Cybercriminals

Threat actors are using AI-generated code to attack critical infrastructure.

Key Highlights

  • The AI-generated tools target specific S7 PLC models manufactured by Siemens.
  • Six different United States federal agencies jointly issued the warning.

The National Security Agency (NSA), Federal Bureau of Investigation (FBI), Department of Energy, Environmental Protection Agency and the Cybersecurity and Infrastructure Agency (CISA) announced on Wednesday that threat actors using AI-generated code targeted Siemens S7 Series programmable logic controller (PLCs).

Let’s try that again in plainer English: Cybercriminals are using AI to attack a piece of hardware that very well might be running on your shop floor.

According to BleepingComputer, these AI-generated attack tools are designed to mimic legitimate monitoring software for Siemens S7 series PLC devices. The custom attack tools constantly monitor the PLCs looking for vulnerabilities and possibly preparing threat actors to launch the attacks that could steal data, shut down equipment on the floor or otherwise interrupt normal operations.

The targeted PLCs include the S7-200, S7-300, S7-400, S7-1200 and S7-1500 models. According to CISA, top mitigation strategies include inventorying all Siemens PLCs, applying security patches, making sure PLCs cannot access the internet, and monitoring for unauthorized activity or anomalies that may indicate compromised security.

This news follows closely on the heels of reported cyberattacks on GE, Philips, Shell and 40 other companies. It also comes soon after coordinated attacks in late July on PLCs at Minnesota water utilities.

Sign up for our eNewsletters
Get the latest news and updates

Voice Your Opinion!

To join the conversation, and become an exclusive member of IndustryWeek, create an account today!