U.S. Agencies Issue Advisory on Active Threat Targeting Siemens S7 Series PLCs
WASHINGTON—The National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency released joint Cybersecurity Advisory AA26-231A on August 19, warning of an active cyber threat to Siemens S7 Series programmable logic controllers (PLCs).
The authoring agencies state that threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations. Actors use Internet scanning services to locate Internet-exposed or poorly protected devices running outdated software.
They employ artificial intelligence (AI)-generated exploitation scripts that incorporate the open-source snap7.dll/python-snap7 library and masquerade as legitimate monitoring tools. These scripts provide read/write access to PLC memory, configuration data, and ladder logic via the S7comm protocol on TCP port 102.
Targeted models include all CPU variants of the S7-200 Series, S7-300 Series (including 314, 315, and 317 models), S7-400 Series, S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, and 1217C), and S7-1500 Series (including F-series safety controllers).
The agencies assess the activity is intended as persistent reconnaissance to develop capabilities and prepare for potential operational effects.
Most Targeted: Manufacturing, Energy, Water, Food And Chemical Facilities
Sectors most targeted are Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Siemens S7 Series PLCs are also used in the Defense Industrial Base.
The advisory notes that ongoing PLC targeting activity is broader than Siemens devices. All PLC owners and operators should apply relevant mitigations. No specific Common Vulnerabilities and Exposures (CVE) identifiers or indicators of compromise (IOCs) are listed in the advisory.
The agencies refer generally to critical and high-severity known vulnerabilities that can be exploited if devices are Internet-exposed or insufficiently segmented. Firmware updates that address known vulnerabilities are available through Siemens ProductCERT.
Unauthorized access could result in disruption of industrial processes, safety incidents, equipment damage, data compromise, cascading effects, and compliance violations, according to the authoring agencies. The advisory explicitly frames its Siemens-specific content as one subset of a wider threat landscape.
Official Statements
-
Federal Bureau of Investigation Cyber Division, August 20, 2026: “The FBI and its partners are warning industrial control system owners and operators about an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs) and are recommending immediate steps to reduce the risk of compromise.”
-
Federal Bureau of Investigation Cyber Division, August 20, 2026: “The threat actors are using scanning services to find internet-exposed PLCs that are running outdated software or otherwise poorly protected.”
-
Federal Bureau of Investigation Cyber Division, August 20, 2026: “The FBI, NSA, CISA, Department of Energy, and EPA urge owners and operators of critical infrastructure to proactively check their systems and review our new Joint Cybersecurity Advisory for technical details and key mitigations.”
-
National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency — Joint Cybersecurity Advisory AA26-231A, August 19, 2026: “The authoring agencies are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them.”
-
National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency — Joint Cybersecurity Advisory AA26-231A, August 19, 2026: “The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected.”
-
National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency — Joint Cybersecurity Advisory AA26-231A, August 19, 2026: “This is not a theoretical risk—it is an active threat.”
-
National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency — Joint Cybersecurity Advisory AA26-231A, August 19, 2026: “Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.”
Full Report & Analysis
The full report includes expert analysis and risk assessment.
Full Report & Analysis →