Federal agencies say hackers are using AI-generated malware to break into the industrial controllers that keep water treatment plants, power grids, and farm equipment running.
A joint advisory from the NSA, FBI, and other agencies warns that attackers are targeting Siemens S7 Series programmable logic controllers (PLCs), using AI-assisted development to chain together exploits and seize control of the devices. The malware is disguised as a monitoring tool to dodge detection, and attackers are finding vulnerable PLCs through internet scanning services. The advisory calls it "an evolution in threat actor capabilities" and says the AI-generated scripts cut the skill and time needed to build working exploits. Agencies are urging operators to pull PLCs off the public internet and patch immediately. Whoever is behind this campaign hasn't been identified.
The real story here isn't really the AI angle. It's that these systems keep getting hit because they're exposed to begin with, sitting on the open internet where anyone running a basic scan can find them.
This is the latest in a string of 2026 attacks on US critical infrastructure. In July, an attack on the operational technology of 30 Minnesota water systems showed indications of Iranian involvement. In April, Rockwell Automation controllers were exploited at water, energy, and government facilities. Automatic Tank Gauge systems at fuel and chemical sites have also been hit, while Russia-linked actors have gone after end-of-life routers abroad. The common thread isn't sophisticated code. It's operational technology that was never built to face the open internet.