A US Advisory Names a German-Made Controller
CISA, the FBI, and the NSA issued a joint advisory on August 20 warning that suspected Iran-linked hackers are using artificial intelligence to generate exploit scripts against Siemens S7 programmable logic controllers.
The advisory covers essentially all internet-connected S7 PLCs, hardware used across water utilities, energy grids, and manufacturing sites, and the agencies confirmed intrusions in Minnesota, Michigan, Arkansas, Georgia, and New Jersey.
AI Turned Public Documentation Into Exploit Code
The agencies said the attackers generated their exploit code with AI models fed on publicly available information about the S7 controllers, not on stolen credentials or insider knowledge of the systems.
That detail matters more than the exploit itself: manipulating a PLC used to require specialist ICS training, and now it requires only the same public manuals every S7 customer receives, fed to a model that writes the attack.
The Same Controller Runs Water and Energy Sites Across Europe
Siemens designs and builds the S7 family in Germany, and the line is deployed at least as heavily across EU water utilities, energy grids, and manufacturing plants as it is in the United States.
No EU or UK authority had issued a matching advisory as of this writing, which leaves European operators reading a US warning about hardware sitting on their own networks, not a warning addressed to them directly.
NIS2 Puts the Exposure on the Operator's Desk
Under NIS2, the liability for a PLC that sits exposed to the internet and unpatched increasingly falls on the operator running it, not on Siemens as the vendor that built it.
An EU or UK operator running S7 controllers on an internet-reachable network should treat this advisory as a today problem rather than a US-only one, because the AI-generated exploit path only requires the documentation their own controllers already ship with.
Read next: Germany's NIS2 Grace Period Has Ended | Gunra Ransomware Runs on Fortinet Bugs Patched in 2025



