Elevated NORTHCOM Washington, DC ยท United States ยท North America

U.S. Agencies Issue Advisory on Active Threat Targeting Siemens S7 Series PLCs

CYBERCOM DISASTERCOM FINCOM
U.S. Agencies Issue Advisory on Active Threat Targeting Siemens S7 Series PLCs

WASHINGTON—The National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency released joint Cybersecurity Advisory AA26-231A on August 19, warning of an active cyber threat to Siemens S7 Series programmable logic controllers (PLCs).

The authoring agencies state that threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations. Actors use Internet scanning services to locate Internet-exposed or poorly protected devices running outdated software.

They employ artificial intelligence (AI)-generated exploitation scripts that incorporate the open-source snap7.dll/python-snap7 library and masquerade as legitimate monitoring tools. These scripts provide read/write access to PLC memory, configuration data, and ladder logic via the S7comm protocol on TCP port 102.

Targeted models include all CPU variants of the S7-200 Series, S7-300 Series (including 314, 315, and 317 models), S7-400 Series, S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, and 1217C), and S7-1500 Series (including F-series safety controllers).

The agencies assess the activity is intended as persistent reconnaissance to develop capabilities and prepare for potential operational effects.

Most Targeted: Manufacturing, Energy, Water, Food And Chemical Facilities

Sectors most targeted are Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Siemens S7 Series PLCs are also used in the Defense Industrial Base.

The advisory notes that ongoing PLC targeting activity is broader than Siemens devices. All PLC owners and operators should apply relevant mitigations. No specific Common Vulnerabilities and Exposures (CVE) identifiers or indicators of compromise (IOCs) are listed in the advisory.

The agencies refer generally to critical and high-severity known vulnerabilities that can be exploited if devices are Internet-exposed or insufficiently segmented. Firmware updates that address known vulnerabilities are available through Siemens ProductCERT.

Unauthorized access could result in disruption of industrial processes, safety incidents, equipment damage, data compromise, cascading effects, and compliance violations, according to the authoring agencies. The advisory explicitly frames its Siemens-specific content as one subset of a wider threat landscape.

Official Statements

Full Report & Analysis

The full report includes expert analysis and risk assessment.

Full Report & Analysis →

Understanding Global Threats

Browse All Topics & Pages

Complete sitemap with all intelligence resources

View Sitemap →

Related Preparedness Gear

Be prepared for evolving situations

Global Conflict Map

Live snapshot of conflict locations and tension zones worldwide.

Last update on: August 19, 2026

Related Alerts

Keep Exploring