U.S. cybersecurity agencies have issued a fresh warning about hackers targeting vulnerable water systems and related critical infrastructure, with Siemens S7 programmable logic controllers now in focus. These devices help manage automated processes in sectors such as water, energy, manufacturing, and agriculture.
The Cybersecurity and Infrastructure Security Agency, the FBI, and the National Security Agency said the attackers are aiming at exposed or outdated controllers, especially those with weak security settings. Officials noted that the activity could lead to service interruptions, operational delays, or damage to essential equipment.
According to the agencies, the latest campaigns are notable for their use of AI to help generate exploit scripts and analyze publicly available technical information. This allows attackers to identify devices that are easier to reach and more likely to be running older software.
CISA has repeatedly advised infrastructure operators to keep industrial systems off the internet whenever possible and to strengthen access controls. The warning is especially relevant for smaller and rural utilities, where a single system may serve a wide area and require careful protection.
The advisory follows a broader pattern of cyber activity affecting water and wastewater providers across several U.S. states, underscoring how connected industrial systems are becoming a central part of digital resilience planning. As AI becomes more embedded in both defense and offense, the future of infrastructure security will depend on faster protection, smarter monitoring, and stronger design.