Security/ ai · security · critical-infrastructure · plc

AI Can Already Hack PLCs, But Not Cheaply Enough to Matter Yet

Forescout researchers ported a working exploit between industrial controllers using AI, but the $500 cost and hands-on effort kept it out of criminals' reach.

Researchers just showed an AI can take a known bug in one industrial controller and turn it into a working exploit for a completely different device.

Forescout researchers set out to test whether AI could help attackers break into operational technology, specifically programmable logic controllers, the boxes that run factory floors, power substations, and water treatment plants. They fed an AI a known remote-code-execution flaw in one PLC and asked it to port that exploit to a second, closed-source device it had never seen before. The AI pulled it off: it first triggered a denial-of-service crash, then built a working exploit capable of running attacker-supplied code on the chip's ARM processor. When the researchers pushed the AI to go further, it bricked the device instead.

The catch is cost. Getting to a working exploit took more than $500 in API usage and heavy hand-holding from human researchers, which makes this a bad trade for the average ransomware crew when phishing and unpatched software still work fine. Nation-state hackers do not have that problem: $500 is nothing against a state intelligence budget, and groups like Sandworm have already shown they will put in the work to hit power infrastructure, as they did against Poland's grid in 2025.

This is not proof that AI-built PLC exploits are coming for every factory tomorrow, but it does show the barrier is a matter of budget, not possibility.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →