AI Is Now Writing the Code That Attacks Your Factory, Water Plant, and Power Grid
Five U.S. agencies just confirmed AI-generated exploit scripts are actively targeting Siemens industrial controllers at water plants, energy facilities, and manufacturers. Here's what every business leader needs to know.
Five U.S. agencies issued a joint advisory last week that deserves every business leader's attention: threat actors are using AI to write custom attack code targeting the industrial controllers that run your water plant, your production floor, your power supply, and your chemical processing facility — and those AI-generated tools work.
The advisory, AA26-231A, was co-signed by the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency. That level of coordination doesn't happen for theoretical risks. It happens when agencies see something active and want to move fast.
Here's what's actually happening — and what it means for your organization.
What the Advisory Says
Attackers are targeting Siemens S7 Series programmable logic controllers (PLCs) — the industrial hardware that physically controls processes at water treatment facilities, energy plants, manufacturing operations, chemical plants, food and agriculture operations, and commercial facilities across the United States.
These controllers have been a known attack target for years. What's new is the weapon.
Threat actors are using Censys and ZoomEye — freely available internet-scanning tools — to find Siemens S7 PLCs with port 102 exposed to the public internet. They then feed that targeting data into AI coding tools, which generate functional Python exploitation scripts using the same open-source industrial automation libraries — snap7.dll and python-snap7 — that engineers use to legitimately communicate with Siemens hardware.
The AI-written code is then disguised as legitimate OT monitoring software. It blends in. It looks like operational traffic. And it gives attackers read-and-write access to PLC memory, configuration data, and ladder logic programs — the code that tells physical equipment what to do.
The advisory's language about this is worth reading directly: "Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools."
Dramatically reducing. That's the phrase that matters.
The Structural Vulnerability
Here's the part that makes this particularly difficult to fix with a software update: for older Siemens S7-300 and S7-400 models, the S7comm protocol was designed with no authentication and no encryption. It was built for closed factory-floor networks — never intended to be connected to the internet.
When that device is reachable over port 102 from anywhere in the world, any IP-level connection can initiate a session and issue read-and-write commands without credentials. There is no password to steal. There is no authentication mechanism to bypass. There is simply access.
Newer S7-1200 and S7-1500 models running updated firmware support S7CommPlus, which includes encryption and authentication. But S7-300 and older S7-400 devices can't be upgraded — the protocol is embedded in hardware. For those devices, the only meaningful mitigation is removing internet connectivity entirely.
Who Is at Risk — And It May Not Be Who You Think
You might read "water treatment plant" and "chemical facility" and assume this is someone else's problem. It isn't.
Consider: you are a customer of water utilities, power grids, food and agriculture operations, and chemical suppliers. If those facilities face operational disruption, your supply chain feels it.
More directly: if you operate any facility with industrial control systems — manufacturing equipment, HVAC controls, building management systems, backup power systems — you have OT assets. And if any of those assets are internet-connected without proper segmentation, you are in scope for exactly the activity described in this advisory.
The Verizon DBIR has documented for years that OT security is the blind spot most businesses don't know they have. Organizations that invested heavily in IT security infrastructure — firewalls, endpoint detection, SIEM platforms — often have dramatically less visibility into their OT environment. Different vendors. Different protocols. Different monitoring tools. Frequently, no monitoring at all.
Adding AI-written exploits to that gap creates a compounding problem: the skill barrier for ICS attacks just dropped, while the detection gap at most organizations has not closed.
The AI Acceleration Problem
This advisory matters beyond Siemens PLCs. It matters because it confirms a structural shift that security professionals have been warning about for 18 months: AI doesn't just help defenders. It helps attackers too — and the help it provides to attackers is often more asymmetric.
Building a functional exploit for an industrial control system previously required specific expertise in S7comm protocol structure, TPKT and COTP framing, PLC ladder logic architecture, and OT network behavior. That expertise was rare. It was a meaningful barrier.
An attacker can now describe the desired behavior in plain language — read the data blocks of a Siemens S7-1200, modify the ladder logic, disable the alarm routine — and receive working code. The barrier has moved.
This is not the last category where AI will move that barrier. It's the current visible example of a trend with much broader implications.
Three Questions for Business Leaders
If you have any operational technology environment — or if your business depends on critical infrastructure providers — these are the questions to be asking your security team this week:
First: Do we have a complete inventory of our OT assets? You cannot protect what you cannot see. If you don't have a current list of every industrial controller, building management system, HVAC controller, and connected operational device in your environment — with their firmware versions, network connectivity, and internet exposure — that inventory needs to happen before anything else. The advisory's first directive is exactly this.
Second: Are any of our OT systems directly reachable from the internet? This should be a hard no. If any Siemens S7 device in your environment has port 102 open to the public internet, that exposure needs to be closed immediately. For any remote access that is operationally necessary, the agencies are specific: route through VPN with multi-factor authentication, not direct port forwarding.
Third: Do we have behavioral monitoring in our OT environment that would detect anomalous S7comm traffic? The advisory provides a specific detection signal: unauthorized use of snap7.dll outside approved systems. A facility whose SCADA platform does not use snap7 that sees snap7 traffic on port 102 should treat it as an active indicator of compromise. If you have no monitoring visibility into your OT network traffic, you would not see this signal.
The Broader Pattern
Last month, Iran-linked hackers shut down a British power plant for four days — the first confirmed instance of Tehran successfully taking down a UK energy facility. The attack ran concurrently with cyberattacks across 12 U.S. states' water infrastructure. The UK government briefed energy company CEOs and wrote to businesses with guidance.
This isn't isolated. It's a pattern. Adversaries — nation-state and criminal — are systematically probing and attacking the operational infrastructure that modern business and society depend on. AI is accelerating their capability to do so.
The appropriate response isn't panic. It's the same thing TrustPoint Cyber recommends for every threat: methodical, risk-prioritized action. Inventory. Isolate. Patch. Monitor. And work with security partners who understand both your IT and OT environment well enough to close the gap between them.
If you're not sure where your organization stands on OT security, that conversation is worth having now — before you're the one briefing your CEO about a four-day outage.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.