A water utility operator in a Freer W.C.I.D. uniform checks a pressure gauge while drawing a water sample from a valve, with pipes and a storage tank in the background.
← Back to Blog
AI Governance

AI-Generated Exploits Just Reached the Machines That Run Your Water

Head portrait of Alex Goryachev
Alex Goryachev·August 21, 2026·5 min read

5 federal agencies named 6 families of Siemens controllers in a single August 19 advisory, warning that AI-assisted scripting now builds working exploits for the equipment running American water, power, and food systems.

Key Takeways

  • A joint advisory from NSA, CISA, the FBI, the Department of Energy, and the EPA (reference AA26-231A, August 19-20, 2026) warns that threat actors are using AI to generate exploit scripts for Siemens S7-200, S7-300, S7-400, S7-1200, S7-1500, and F-series safety controllers.
  • The advisory states that AI is dramatically reducing the technical expertise required to build these tools, which pair open-source libraries such as snap7.dll and python-snap7 with AI-assisted scripting to read and write PLC memory, configuration data, and ladder logic over the S7comm protocol.
  • Attackers locate victims by scanning services like Censys and ZoomEye for internet-exposed controllers running default or weak credentials, then disguise their tooling as legitimate OT monitoring software.
  • Three escalations in five months: Iranian-linked hackers targeted Rockwell Automation Allen-Bradley PLCs in April 2026, an attack caused equipment malfunctions at more than 30 Minnesota water utilities in July 2026, and the Siemens S7 advisory landed on August 19-20, 2026.

On August 19, 5 federal agencies named the exact hardware: Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers, plus the F-series safety controllers, all of them now targeted by exploit scripts built with AI assistance. The joint advisory carries the reference AA26-231A and comes from NSA, CISA, the FBI, the Department of Energy, and the EPA together. Those controllers open and close valves at water treatment plants, run food production lines, and hold chemical processes inside their safety limits.

The method is documented in plain terms. Attackers pair 2 open-source libraries, snap7.dll and python-snap7, with AI-assisted scripting to build tools that read and write PLC memory, configuration data, and ladder logic programs over the S7comm protocol. The finished tool is dressed to look like legitimate OT monitoring software, the kind a plant engineer would expect to see on the network. Finding targets takes even less effort than building the tool. Attackers scan with services like Censys and ZoomEye for devices sitting on the open internet with default or weak credentials, and then they walk in.

The advisory states its assessment without hedging.

"This is not a theoretical risk," the joint advisory states. "It is an active threat."

The same document names what changed underneath that sentence. AI is dramatically reducing the technical expertise required to build these tools. Everything else in the advisory follows from that one clause.

The people who run these plants were never hired to be security analysts

In July, an attack hit more than 30 Minnesota water utilities and caused equipment malfunctions. Consider what that week looked like for the operator of a small municipal system, someone whose job is chlorine levels, pump schedules, and a state compliance report due Friday. That person spent the week answering a question they were never trained to answer: is the water leaving this plant safe right now. They did not choose a career in cyber defense. A few thousand people brushed their teeth that morning on the assumption that somebody had it handled, and the somebody was them.

That is the kitchen-table version of an OT security story, and it is the accurate one. Sectors named in the advisory include critical manufacturing, energy, water and wastewater systems, chemical, food and agriculture, and commercial facilities. Every sector on that list ends at a tap, a light switch, or a grocery shelf.

The escalation has a date-stamped record

3 incidents inside 5 months show the direction of travel clearly enough that nobody has to speculate about it.

DateTargetWhat happened
April 2026Rockwell Automation / Allen-Bradley PLCsIranian-linked hackers targeted the controllers, and a warning was issued.
July 2026More than 30 Minnesota water utilitiesAn attack caused equipment malfunctions across the affected systems.
August 19-20, 2026Siemens S7-series and F-series controllersJoint NSA, CISA, FBI, Department of Energy, and EPA advisory AA26-231A on AI-generated exploit scripts.

The April and July entries describe attackers doing skilled work. The August entry describes attackers getting the same result with far less of it. That shift showed up from the builder's side earlier this year too, when OpenAI paused training on a model that reached a critical cyber-risk tier, and again in the disclosure of an AI agent running a cyberattack on its own. The same capability, seen from opposite ends of the industry.

Industrial controllers run on a slower clock than the people attacking them

Several of these Siemens families have been in service for years, some of them for decades, and that longevity is deliberate. You cannot push a hotfix to a water treatment plant the way a phone pushes an app update. A controller change means a validation cycle, a maintenance window, a plant shutdown, and a signature from someone who is accountable if the chlorine dosing goes wrong afterward. Slow is the safety feature. It has kept people alive for a long time.

That design carried one assumption inside it: an attacker also needed months, a lab, and a specialist who understood S7comm at the byte level. AI removed the specialist. The patch calendar and the review cycles stayed exactly where they were, because they were written when the other side moved at roughly the same speed. This is what rules written for a slower world look like in practice, and it is the governance problem of this decade in one sentence.

The half-life of skills runs in both directions here. The specialist expertise it took to write a working S7comm exploit is evaporating, which is why the advisory exists. The expertise a defender spent a career building sits on the same clock, and the defender's institution reviews its rules once a year.

Credit where it is earned: 5 agencies published a coordinated, plainly worded advisory within days of each other, naming model families, libraries, protocols, and the scanning services attackers use. That is fast, specific, cross-agency work, and it hands operators something they can act on this week rather than a paragraph of caution. I advise the California State University system's AI Working Group on AI governance, and its rule-making calendar has the same shape as an OT patch cycle: annual review and careful sign-off. Deliberate is correct for any institution carrying public trust. The work now is shortening the distance between what an attacker can build in an afternoon and what a rule written last year anticipated.

Here is the question worth carrying into your next operations meeting. If the time to build an exploit for our equipment fell from months to an afternoon, what is our matching number for noticing one, and who exactly is expected to hold that line at 2 a.m. on a Sunday? If your answer is a person, name them. If it is a vendor, read the contract.

And if you run a small system with no security staff and no budget for one, that question still belongs to you. Ask your state program and your equipment vendor what they will fund, and ask this month. The advisory gave every operator in the country the same information on the same day, which is the rarest advantage in this work. Attackers now relearn in an afternoon. The institutions protecting your water relearn on a calendar, and closing that difference is the governance work of the next 30 days. If your utility is doing that work, I am easy to find.

How can a water utility check whether its own PLCs are exposed to the internet?

The advisory describes attackers using public scanning services such as Censys and ZoomEye to find controllers reachable from the open internet, and a utility can run the same searches against its own public IP ranges. Any S7comm-capable device that answers from outside the plant network, especially one still holding default or weak credentials, is the first thing to pull behind a firewall.

What is CISA advisory AA26-231A?

AA26-231A is the reference number for the joint cybersecurity advisory published August 19-20, 2026 by NSA, CISA, the FBI, the Department of Energy, and the EPA. It warns that threat actors are using AI to generate exploit scripts targeting Siemens S7-series programmable logic controllers across critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities.

Which Siemens PLC models does the AI exploit advisory cover?

The advisory names the S7-200, S7-300, S7-400, S7-1200, and S7-1500 controller families, along with the F-series safety controllers. Access is described over the S7comm protocol using the open-source snap7.dll and python-snap7 libraries paired with AI-assisted scripting.

Here is what makes Alex a credible voice on this topic: Alex Goryachev advises the California State University system's AI Working Group on AI governance, and he shaped a $1.1B innovation portfolio at Cisco as Managing Director of Innovation Strategy and Head of Global Innovation Centers, 20 years spent inside the networking industry that connects the operational technology these Siemens controllers sit on.

If your organization is deciding how fast its own rules need to move, book a conversation →

← Back to Blog
Head portrait of Alex Goryachev
Alex Goryachev

WSJ-bestselling author · Former Managing Director of Innovation, Cisco · Advisor, CSU AI Working Group · LinkedIn Top AI Voice

Work with Alex

Bring this thinking to your organization

Alex works with executive teams at global enterprises on AI strategy, governance frameworks, and organizational readiness. Available for keynotes, C-suite workshops, and advisory engagements.