Blogerroom logoBlogerroom
AI
AI

Feds Warn AI Scripts Are Now Attacking US Water Systems

AB
Mr. Aayush BhattAugust 22, 20268 min read
๐ŸŒ Language

Feds Warn AI Scripts Are Now Attacking US Water Systems

Five US agencies warned hackers are using AI-generated scripts against Siemens controllers running water systems in 12+ states.

Five separate US federal agencies do not typically issue a joint warning together unless something has already gone wrong. On Wednesday, August 19, the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency published exactly that kind of advisory, stating in language stripped of the usual bureaucratic hedging that hackers using AI-generated scripts to attack the industrial controllers running America's water systems is "not a theoretical risk, it is an active threat."

What Is Actually Being Targeted

The devices at the center of the advisory are Siemens S7 Series programmable logic controllers, small industrial computers that physically open valves, run pumps, and operate machinery at water treatment plants, power stations, and factories. According to TechCrunch's reporting on the advisory, agencies said hackers are targeting "all" Siemens S7 PLCs connected to the internet, spanning energy, water systems, manufacturing, and agriculture. The sectors named as most heavily targeted were critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, according to Help Net Security's coverage, a list that covers most of the infrastructure an ordinary person depends on without ever thinking about it.

The mechanism is specific and worth understanding on its own terms. Threat actors are combining open-source industrial automation libraries, specifically snap7.dll and python-snap7, with AI-assisted scripting to build custom tools disguised as legitimate monitoring software. In plain terms, attackers are using AI to help write exploitation code faster and more convincingly than they could manually, then dressing that code up to look like the routine diagnostic software a plant operator would expect to see running on their own network.

The Attacks That Prompted This Warning

This advisory did not emerge from a hypothetical threat model. It followed a documented, ongoing campaign against real infrastructure. According to Cybersecurity Dive's reporting, utilities in at least 12 states have been affected, including Minnesota, Michigan, Georgia, South Dakota, and New Jersey. The most concrete incident cited across multiple outlets involved a coordinated cyberattack that hit operational technology systems at more than 30 community water utilities across Minnesota on July 26 and 27, an event that came just days after a prior CISA update had expanded its warnings to cover Schneider Electric and Siemens devices in addition to the Rockwell Automation controllers named in an earlier April advisory.

Federal News Network's reporting on CISA's own guidance described the specific tactics observed: threat actors targeting exposed PLCs had modified operator passwords to lock legitimate staff out of their own systems, and in some cases disconnected controllers entirely by changing their IP addresses. That is not reconnaissance or probing. That is active operational disruption of equipment responsible for treating the water people drink.

The Attribution Nobody Will Officially Confirm

Several outlets, including Forbes and an academic review of the underlying campaign, have linked this activity to Iranian government-affiliated actors, tracing the pattern back through a formal joint advisory issued April 7 under the designation AA26-097A, which specifically named exploitation of Rockwell Automation and Allen-Bradley controllers by actors linked to Iran's IRGC and operating under the persona CyberAv3ngers. That persona has a documented history stretching back to a 2023 campaign against Unitronics industrial controllers, meaning this is not a new actor but an established one that has simply expanded its target list and, now, its tooling.

Nick Andersen, CISA's acting director, was more cautious in his own public remarks. Speaking to Nextgov/FCW roughly a week after the initial water-sector warning, Andersen confirmed the agency was working with the FBI to help affected utilities recover but stopped short of formally attributing the intrusions to any specific group. That gap between what outside researchers and reporting have pieced together and what the government will say on the record is a familiar pattern in critical infrastructure incidents, where formal attribution carries diplomatic and legal weight that agencies are often reluctant to commit to publicly while an investigation remains active.

Why AI Changes the Calculus Here, Specifically

The technical vulnerabilities being exploited, internet-exposed industrial controllers with weak or default authentication, are not new. Security researchers have warned about exposed PLCs for the better part of a decade. What has changed, according to the joint advisory's own framing, is the speed and sophistication with which attackers can now generate working exploitation tools. AI-assisted scripting lowers the technical bar for building convincing, functional attack tooling, letting a threat group iterate faster and disguise malicious tools as legitimate software more effectively than manual development would typically allow.

This mirrors a pattern already well documented elsewhere this year, where AI systems have repeatedly demonstrated an ability to independently find and exploit real vulnerabilities faster than human defenders can patch them. The JADEPUFFER ransomware operation earlier this year showed an AI agent chaining together reconnaissance, credential theft, and system compromise entirely on its own, without a human directing individual steps. The water-system campaign described in this advisory is not fully autonomous in the same way, human operators are still directing the overall campaign, but it demonstrates the same underlying trend: AI tools accelerating and refining the attack development process even when a human remains in the loop.

A Familiar Pattern From a Different Adversary

This also lines up closely with a separate incident disclosed just days earlier, when Microsoft's August Patch Tuesday release revealed that North Korea's Lazarus Group had already been exploiting a Windows kernel flaw for roughly two months before a fix existed, deploying a rootkit through a campaign of old-fashioned human exploit development rather than AI assistance. Two different nation-state-linked campaigns, disclosed within roughly a week of each other, targeting different infrastructure through different methods, illustrate the same underlying reality: state-sponsored threat actors are running persistent, well-resourced operations against both consumer software and industrial control systems simultaneously, and only one of those campaigns needed AI assistance to be effective. The Lazarus campaign succeeded through patient, purely human security research. The water-system campaign shows what happens when that same patience gets paired with AI-accelerated tooling.

The Mitigation Advice Nobody Wants to Hear

The most pointed observation about this entire advisory came from Techopedia's own coverage, which noted dryly that one of the most effective defenses against a sophisticated, AI-assisted nation-state campaign remains disarmingly simple: do not connect a programmable logic controller directly to the public internet in the first place. That is not a cutting-edge cybersecurity recommendation. It is basic network hygiene that has been standard security guidance for well over a decade, and CISA's own reporting confirms that exposed water system controls are still being found connected to the open internet even now, in the middle of an active, multistate hacking campaign.

That gap, between well-established basic security practice and what is actually deployed in the field across thousands of small water utilities with limited IT budgets and staff, is the real vulnerability this advisory describes. AI-generated exploit scripts make attacks faster and cheaper to develop. They do not change the fact that the underlying weakness, an industrial controller sitting exposed on the public internet with weak authentication, was preventable using security practices that predate AI entirely. Cybersecurity Dive's reporting notes that support is now growing among officials for minimum cybersecurity standards and additional federal funding specifically for utilities, a policy response that has been proposed before past incidents and never fully implemented. Whether this advisory, following real attacks across a dozen states, finally produces binding requirements rather than another round of voluntary guidance is the open question this warning leaves for Congress and regulators to answer.

What Happens if This Pattern Continues

Congress has already moved once this year to address the broader risk of AI systems acting with insufficient oversight, introducing legislation requiring frontier AI labs to maintain a working kill switch for their most capable models. That bill was written with AI labs and their own models in mind, not with AI-assisted attack tooling built by outside threat actors using open-source libraries. This advisory is a reminder that the AI risk conversation in Washington has, so far, focused heavily on what frontier labs' own models might do if left insufficiently constrained. It has focused considerably less on how those same AI capabilities, once broadly available, get weaponized by hostile actors against physical infrastructure that has nothing to do with any AI company at all. A joint advisory from five federal agencies, following real attacks on real water utilities across a dozen states, is the clearest evidence yet that the second half of that risk equation deserves at least as much regulatory attention as the first.

ShareWhatsAppTwitterLinkedIn
AB

Written by

Mr. Aayush Bhatt

Software Engineer interested in how models work and where they fail.

โ† Back to AI