Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Feds Sound Alarm on Active Hacking Campaign Targeting Siemens S7 PLCs Nationwide
Feds Sound Alarm on Active Hacking Campaign Targeting Siemens S7 PLCs Nationwide
Read Time:3 Minute, 15 Second

A live threat aimed at America’s industrial floor

Five federal agencies — the NSA, CISA, the FBI, the Department of Energy and the EPA — have jointly issued an advisory warning that hackers are actively targeting Siemens S7-series programmable logic controllers (PLCs) inside U.S. critical infrastructure. The agencies describe it as a “live, ongoing threat,” but one built around patient reconnaissance and capability-building rather than an immediate push to trigger physical sabotage. That distinction matters: it suggests the intruders are positioning themselves for a future moment of their choosing, not necessarily acting today.

PLCs like the S7 family are the small industrial computers that physically open valves, run conveyor belts, and trip safety interlocks. They rarely make headlines, but they are the layer where a cyberattack stops being abstract and starts being physical.

Which controllers are in the crosshairs

The advisory names the full spread of Siemens’ S7 lineup as potentially exposed, including legacy and current-generation hardware still common on factory floors and in utility substations:

  • S7-200 and S7-300 (older, widely deployed legacy units)
  • S7-400
  • S7-1200 and S7-1500 (current-generation controllers)
  • F-series safety controllers, which govern emergency shutdown and interlock functions

The inclusion of safety controllers is notable, since tampering with interlocks or shutdown logic — rather than the production process itself — is one of the more dangerous outcomes regulators worry about.

How the intrusions are unfolding

According to the advisory, the attackers are not relying on a single exotic flaw. Instead they’re chaining together internet-wide scanning services such as Censys and ZoomEye to find exposed devices, then using open-source engineering libraries — specifically snap7.dll and the Python python-snap7 wrapper — to talk to the controllers over the S7comm protocol. Investigators also flagged the use of AI-assisted tooling to help generate and refine exploitation code, and instances of malicious code disguised as legitimate operational-technology monitoring software. In several cases, the path of least resistance was simply default or barely-changed device credentials.

The agencies point to a pattern rather than an isolated incident, tying this campaign to a string of recent intrusions at water utilities in Georgia, Minnesota and Michigan as evidence that operational technology is being probed at scale.

Sectors named in the advisory

The warning spans a wide swath of the economy that relies on Siemens automation gear:

  • Critical manufacturing
  • Energy
  • Water and wastewater systems
  • Chemical facilities
  • Food and agriculture
  • Commercial facilities
  • The defense industrial base

The potential fallout ranges from disrupted production runs to more serious safety events if interlocks or emergency shutdown logic are manipulated, plus the kind of extended downtime and supply-chain ripple effects that follow any major OT outage.

What the advisory tells defenders to do

The recommended response is largely blocking-and-tackling OT hygiene, but the agencies stress urgency:

  • Build a complete inventory of every S7 device on the network
  • Apply the latest Siemens firmware and security patches
  • Block TCP port 102 at the network perimeter and confirm no PLC is directly internet-facing
  • Restrict engineering access — TIA Portal and STEP 7 — to authorized workstations only
  • Deploy ICS-aware intrusion detection and watch for anomalous S7comm traffic, unauthorized write operations, off-hours connections, and processes importing snap7.dll
  • Share the advisory with integrators and managed service providers who touch the environment
  • Report suspicious activity to CISA or the FBI’s Internet Crime Complaint Center

Why this one is different

Industrial control system warnings aren’t new, but the combination of five agencies co-signing, AI-assisted exploit tooling, and an explicit tie to recent water-sector incidents signals that officials see this as an active, evolving campaign rather than a theoretical risk. Organizations running S7 hardware — even older, “it’s always worked fine” units — should treat the port 102 and credential-hygiene items on this list as immediate priorities, not the next maintenance-window task.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Feds Sound Alarm on Active Hacking Campaign Targeting Siemens S7 PLCs Nationwide, use the discussion on Forum.

>> forum community

Comments

Leave a Reply