Federal agencies warn of active cyber threat to Siemens PLCs
Federal cybersecurity and environmental agencies are warning water and wastewater utilities of an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs), particularly systems that are exposed to the internet or have outdated software and weak access controls.
The advisory from the National Security Agency, Cybersecurity and Infrastructure Security Agency, FBI, Department of Energy and EPA said threat actors are using internet scanning services and AI-assisted scripts to identify and target vulnerable Siemens PLC installations. The activity includes attempts to gain read/write access to PLC memory, configuration data and ladder logic.
The agencies said water and wastewater is among the critical infrastructure sectors most targeted by the activity. A compromised PLC could potentially disrupt treatment processes, damage equipment, cause safety incidents or result in operational downtime.
The advisory urges utilities to immediately inventory Siemens S7 PLCs, apply applicable security patches, ensure controllers are not internet-accessible and strengthen access controls. Utilities are also encouraged to segment operational technology networks, enable logging and monitoring and investigate unusual S7comm activity.
The agencies specifically highlighted the risk posed by third-party service providers and system integrators that have remote access to PLCs. Utilities are encouraged to ensure those connections are appropriately secured and monitored.
The advisory applies to Siemens S7-200, S7-300, S7-400, S7-1200 and S7-1500 series PLCs. The agencies emphasized that PLC targeting activity extends beyond Siemens equipment and encouraged owners and operators of all PLCs to review applicable cybersecurity protections.



