Federal Agencies Warn of Cyberthreats to Industrial Control Systems
Federal agencies are warning operators of critical infrastructure that hackers are actively targeting Siemens S7 Series programmable logic controllers used in water systems, factories, energy facilities and other industrial environments. An advisory from the NSA, FBI, Department of Energy, Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency described an active threat to equipment that monitors and controls physical processes.
According to officials, attackers are scanning the internet for controllers that are exposed or inadequately protected. They may also be using artificial intelligence-generated tools to reduce the time and expertise needed to identify weaknesses and gain access. The agencies said some activity appears intended to study industrial networks and develop capabilities that could later disrupt operations.
A successful intrusion could halt production, interrupt public services, damage equipment, create safety risks and produce wider supply chain effects. Because industrial systems are often interconnected, an incident at one facility could affect other businesses, utilities or communities. Officials noted that operators may not know their equipment is accessible online, particularly when vendors maintain remote access.
The warning follows an increase in reported attacks against programmable logic controllers and local water systems. CISA previously reported activity involving equipment from Siemens, Rockwell Automation and Schneider Electric, including attacks associated with Iranian-affiliated hackers. Minnesota also reported at least 30 cyber incidents involving local water systems on July 26 and 27. Federal authorities have not formally attributed those incidents to Iran.
Siemens said it was coordinating with CISA but had not observed higher attack levels or identified previously unknown vulnerabilities in its industrial control products. The company said its ProductCERT team would provide updates to potentially affected customers.
The advisory highlights a distinction between conventional data breaches and attacks on operational technology. While both can cause financial harm, industrial intrusions may also produce physical consequences.