- NSA has warned of reconnaissance activity targeting Siemens S7 PLCs
- AI-generated scripts are being used to probe industrial control systems
- The 2026 Intel Summit on Sept. 24 will focus on AI, cyber and intelligence capabilities
The National Security Agency and other agencies have issued a cybersecurity advisory warning of cyber actors conducting targeted reconnaissance against U.S.-based Siemens S7 Series programmable logic controllers, known as PLCs.
What Threats Are Targeting Siemens PLCs?
The advisory, titled “Defending Against an Active Threat to Siemens S7 Series PLCs,” warns that threat actors are using artificial intelligence-generated exploitation scripts, masked as legitimate monitoring tools, to conduct targeted reconnaissance and build attack capabilities against the devices, NSA said Wednesday.

AI-enabled cyber threats are creating new challenges for intelligence and national security organizations. The Potomac Officers Club’s 2026 Intel Summit on Sept. 24 will bring together intelligence leaders and industry executives to discuss AI, cyber capabilities, data and secure information-sharing. Register now!
These cyber actors are targeting critical manufacturing, energy generation and distribution, chemical processing, water and wastewater treatment, commercial facilities, and food and agriculture production.
The agencies cautioned that inadequately secured PLCs leave industrial environments vulnerable to disruptions, safety incidents, equipment damage and downtime. Other potential consequences include compromised sensitive data and regulatory compliance violations.
The warning follows earlier federal advisories on malicious activity targeting internet-connected PLCs. In April, agencies reported that Iran-affiliated actors had targeted Rockwell Automation and Allen-Bradley PLCs, with some activity involving unauthorized changes to project files and data displayed on human-machine interfaces and supervisory control and data acquisition systems.
A subsequent update broadened the scope of the warning to include Siemens and Schneider Electric PLCs, showing that the threat activity was not limited to a single manufacturer.
What Security Measures Does NSA Recommend?
The advisory urges PLC owners and operators to apply security patches, isolate devices from the internet where possible and adopt strong access controls, while monitoring industrial control system environments for unusual or malicious activity.
The agencies further called for coordination among relevant teams as detection and prevention measures are put in place.
The guidance applies to national security systems within the defense industrial base and the Department of War.




