US warns of active cyber threat targeting critical infrastructure
Heritage Foundation Vice President Victoria Coates joins ‘Mornings with Maria’ to discuss escalating Iran tensions, Russia’s reported support for Tehran, Ukraine’s massive drone attack and foreign partnerships at U.S. universities.
Federal agencies are warning that hackers are actively targeting industrial control systems used across U.S. water plants, factories, energy facilities and other critical infrastructure.
The NSA, FBI, Department of Energy, EPA and Cybersecurity and Infrastructure Security Agency said Wednesday there is an “active threat” targeting Siemens S7 Series programmable logic controllers.
Siemens said Thursday that it had not detected an increased level of attacks or any previously unknown vulnerabilities affecting its industrial control systems products.
The devices are used to monitor and control industrial equipment across sectors including manufacturing, energy, water and wastewater, chemicals, food and agriculture.
A successful attack could disrupt critical operations, force facilities offline, damage equipment and create safety hazards, according to the advisory. Officials also warned that breaches could trigger cascading disruptions across interconnected systems.
THOUSANDS OF NORTH KOREAN IT WORKERS ARE INFILTRATING CORPORATE AMERICA

The Siemens booth at CES 2024, the world’s largest annual consumer technology trade on Jan. 10, 2024, in Las Vegas. (Tayfun Coskun/Anadolu via Getty Images)
The government said hackers are increasingly using artificial intelligence to make such attacks easier, dramatically reducing the expertise and time needed to develop tools capable of exploiting industrial systems.
According to the advisory, attackers are scanning the internet for exposed or poorly protected Siemens controllers and using AI-generated tools to help gain access to them.
Federal agencies said the activity appears aimed in part at studying targeted systems and developing the ability to disrupt operations in the future.
Such attacks could affect production, public services and supply chains, while also causing equipment damage or prolonged downtime.
Officials also warned that some operators may not realize their systems are exposed, particularly when outside vendors have remote access to industrial equipment.

The Siemens logo at the virtual annual shareholder meeting in Munich, Germany, Feb. 10, 2022. (Sven Hoppe/Pool via Reuters)
The warning comes amid a recent wave of cyberattacks against local water systems that cybersecurity experts suspect may have links to Iran, though federal officials have not formally attributed those incidents to Tehran.
CISA warned July 30 of a significant increase in attacks targeting programmable logic controllers. Days earlier, the agency said Iranian-affiliated hackers had been exploiting industrial equipment made by Siemens, Rockwell Automation and Schneider Electric.
RUSSIAN HACKERS EXPLOITING VULNERABLE INTERNET ROUTERS, NSA WARNS
Concerns intensified after Minnesota became…
Read More: US warns of active cyber threat targeting critical infrastructure