A new joint cybersecurity advisory from the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA), is warning industrial organizations of an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs).
This is not simply a newly discovered vulnerability or theoretical attack scenario. According to the advisory, threat actors are actively conducting reconnaissance and capability development against U.S.-based Siemens PLC installations, particularly systems that are exposed to the Internet, running outdated software, or otherwise insufficiently protected. Particles Plus is sharing this information as an awareness notice for customers operating industrial, manufacturing, laboratory, cleanroom, and other facilities where monitoring equipment may exist within a larger operational technology (OT) environment.
The advisory does not identify Particles Plus particle counters or monitoring systems as affected products. The concern is the security of PLCs and the broader industrial networks in which connected equipment may operate.
What Is Happening?
According to the joint advisory, threat actors are using Internet scanning services to identify exposed or poorly segmented Siemens S7 PLCs. They are then using publicly available industrial automation tools along with AI-assisted exploitation scripts to accelerate the development of attack capabilities.
The advisory specifically describes malicious scripts using the snap7.dll/python-snap7 library. These tools can mimic legitimate OT monitoring software while providing read/write access to PLC memory, configuration data, and ladder logic through the S7comm protocol.
The agencies warn that artificial intelligence is significantly reducing the expertise and time required to develop working industrial-control-system exploitation tools, allowing attackers to identify vulnerabilities, modify attack techniques, and potentially target exposed systems more quickly.
Which Siemens PLCs Are Being Targeted?
The advisory identifies active targeting of the following Siemens PLC families:
- S7-200 Series
- S7-300 Series
- S7-400 Series
- S7-1200 Series
- S7-1500 Series, including F-series safety controllers
Importantly, the agencies also caution that current PLC targeting activity extends beyond Siemens devices. Organizations using other PLC platforms should therefore consider the recommended cybersecurity practices as part of their broader OT security strategy.
Why This Matters
PLCs frequently sit at the heart of industrial automation. Unauthorized access to these systems can have consequences that extend beyond traditional IT cybersecurity. The agencies warn that compromised PLCs could potentially result in:
- Disruption of industrial processes and production
- Changes affecting product quality
- Safety incidents caused by manipulation of process parameters or safety systems
- Equipment damage or extended downtime
- Exposure of proprietary process information and facility configurations
- Cascading impacts across interconnected systems
- Regulatory compliance issues and potential liability
The advisory identifies Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities among the sectors most frequently targeted by the observed activity.
Key Takeaway
If your organization operates Siemens S7 PLCs:
- Inventory them.
- Patch them.
- Remove direct Internet exposure.
- Review remote access.
- Strengthen authentication.
- Monitor S7comm traffic.
Importantly, even if you do not use Siemens PLCs, this advisory is a good reason to review how PLCs and other connected industrial devices are protected within your OT environment. The joint advisory is marked TLP, meaning the information may be broadly shared to help reach affected organizations and stakeholders.
Source: Joint Cybersecurity Advisory, Defending Against an Active Threat to Siemens S7 Series PLCs, NSA, CISA, FBI, DOE and EPA, August 2026. https://media.defense.gov/2026/Aug/18/2003983494/-1/-1/0/CSA_Active_Threat_to_Siemens_S7_Series_PLCs.PDF