AI-Assisted Attacks Target Water Systems
US agencies warn hackers are exploiting Siemens PLCs in critical infrastructure with AI-generated scripts.
U.S. security agencies are sounding the alarm about a new wave of cyberattacks against water systems, with hackers now using artificial intelligence to break into critical devices. The joint advisory, published Wednesday, points to an evolving threat that could have serious consequences for communities that rely on these systems.
Joint Advisory on Siemens PLCs
CISA, the FBI, and the National Security Agency, along with other agencies, said on Wednesday that hackers are targeting “all” Siemens S7 programmable logic controllers (PLCs). These devices are used to control automated processes in energy, water systems, manufacturing, and agriculture.
The advisory describes the activity as part of broader efforts against water supply and wastewater systems across the United States. Disruptions could result in downtime, safety incidents, or equipment damage, the agencies warned.
AI-Generated Exploit Scripts
The hackers are reportedly using AI to generate exploit scripts that rely on publicly available information to find and target vulnerable PLCs. This includes devices running outdated software or that are otherwise poorly secured.
An incident response professional who works with critical infrastructure told TechCrunch it was noteworthy that hackers are using AI to identify and target vulnerable PLCs, as well as to understand how these devices work. But he cautioned that these devices are already highly vulnerable to begin with.
Longstanding Warnings, Unheeded
CISA has long warned owners of critical infrastructure to keep these devices disconnected from the internet. Officials have acknowledged that rural communities are often the most affected because these systems service large geographic areas.
This latest warning follows a series of cyberattacks by suspected Iranian hackers targeting U.S. water suppliers and wastewater providers in recent months. CISA said the attacks have escalated since Iranian hackers first targeted internet-connected systems used in critical infrastructure.
Reported Intrusions Across States
Officials across the U.S. have reported intrusions at water facilities in Minnesota and Michigan, as well as Arkansas, Georgia, and New Jersey.
These incidents underscore the widespread nature of the threat, affecting systems that serve both small and large communities.
Why It Matters
For the operators of water systems and other critical infrastructure, this advisory is a clear signal that attackers are not standing still. The use of AI to generate exploits could lower the barrier to entry for cybercriminals, even as the underlying devices remain dangerously exposed.
For businesses and consumers, this suggests that disruptions to water services could become more frequent and more severe if operators do not act quickly to secure their systems. The advisory makes clear that the attack surface is vast, and the time to shore up defenses is now.
Sources
- TechCrunch Original source
Continue Reading
Android Banking Trojans Gain On-Device Fraud Tools
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.
Citrix NetScaler flaws: patch gap may invite attackers
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
NCSC's Agentic AI Controls Raise the Stakes for Autonomy
UK NCSC issues interim guidance urging sandboxing, human oversight, and access limits for agentic AI systems.