US security agencies are warning that hackers are using artificial intelligence to accelerate attacks against industrial control systems, including equipment responsible for running water and wastewater facilities.
The campaign puts a new spotlight on a longstanding weakness in critical infrastructure: programmable industrial equipment that was designed to operate physical processes reliably, but was not necessarily built for a world where internet-connected systems can be searched, studied and targeted at machine speed.
TechCrunch reports that CISA, the FBI and the National Security Agency are warning of active attacks against Siemens S7 programmable logic controllers, or PLCs, used across water systems, energy, manufacturing and agriculture.
PCMag’s report similarly frames the threat as hackers targeting US industrial and water systems with the help of AI, underscoring that the issue reaches beyond conventional corporate networks into operational technology controlling physical infrastructure.
AI Is Compressing the Time Needed to Build Exploits
The most significant technical shift is how attackers are using AI.
Hackers are generating exploit scripts with AI using publicly available information about vulnerable PLCs, particularly systems running outdated software or lacking adequate security controls.
That changes the economics of industrial cyberattacks.
Attackers historically needed specialized knowledge of operational technology, industrial protocols and individual controller families. AI does not eliminate that expertise entirely, but it can help automate research and code generation, shrinking the amount of time required to turn known weaknesses into usable attack tools.
TechCrunch cites a critical-infrastructure incident responder who said it was notable that attackers were using AI both to identify vulnerable PLCs and to understand how the devices operate, while stressing that many of the systems were already highly vulnerable.
That distinction matters: AI is accelerating an existing infrastructure problem rather than creating it from scratch.
Siemens PLCs Sit Deep Inside Physical Infrastructure
Programmable logic controllers are specialized computers responsible for automating physical processes. Unlike an ordinary compromised laptop, a compromised PLC can affect machinery, pumps and industrial operations.
US agencies warned that compromises involving Siemens S7 controllers could lead to downtime, safety incidents or equipment damage in critical infrastructure.
The agencies described the threat as targeting “all” Siemens S7 PLCs, significantly widening the relevance of the warning for industrial operators using the controller family.
For companies building industrial cybersecurity products, that increases demand for technologies that can discover exposed equipment, monitor unusual PLC activity and segment operational networks before an attacker reaches the control layer.
Water Utilities Expose the Limits of Legacy OT Security
The warning follows a series of attacks against US water infrastructure.
Suspected Iranian hackers have targeted US water suppliers and wastewater providers in recent months, while incidents involving water facilities have been reported in Minnesota, Michigan, Arkansas, Georgia and New Jersey.
CISA has long warned infrastructure operators against leaving industrial controllers directly exposed to the internet, noting that rural communities can be particularly affected because individual systems may serve large geographic areas.
PCMag’s coverage also places industrial and water infrastructure at the center of the FBI warning, reinforcing how cyber risk is moving from data theft toward systems capable of affecting physical operations.
AI Changes the Threat Model for Industrial Security Builders
For cybersecurity teams, the larger lesson is that weak infrastructure is becoming easier to exploit at scale.
An internet-exposed controller running old software was already a security problem. AI-assisted reconnaissance and exploit generation can potentially make finding and targeting those systems faster and accessible to a broader group of attackers.
That shifts the pressure onto industrial-security vendors, infrastructure operators and engineering teams. Defending operational technology increasingly means designing for an environment where attackers can use AI to rapidly study public documentation, generate code and iterate against known weaknesses.
The emerging security race is therefore not simply AI versus AI.
It is a race between increasingly automated attackers and infrastructure that, in many cases, was deployed long before anyone expected software agents to help adversaries search for the weakest machine connected to the network.