READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Feds Warn AI Is Now Writing the Scripts Hackers Use to Break Into Water Plants

Feds Warn AI Is Now Writing the Scripts Hackers Use to Break Into Water Plants
CISA, the FBI, NSA, DOE, and EPA issued a joint advisory on August 19 warning that hackers are using AI-generated scripts disguised as monitoring tools to target Siemens S7 PLCs across water, energy, and food sectors. It follows a late-July attack on more than 30 Minnesota water systems that officials say may be linked to Iran, though no formal attribution has been made. Bottom line for taxpayers: local water utilities are running critical infrastructure on outdated, internet-exposed hardware, and Washington is now telling them AI just made the attackers faster.

The federal government just admitted hackers are using artificial intelligence to break into the machines that run America's water plants.

On August 19, CISA, the NSA, the FBI, the Department of Energy, and the EPA published a joint advisory titled "Defending Against an Active Threat to Siemens S7 Series PLCs." The agencies said threat actors are running reconnaissance against U.S.-based Siemens programmable logic controllers using AI-generated exploitation scripts built to look like legitimate monitoring software.

Programmable logic controllers, or PLCs, are the small industrial computers that run pumps, valves, and treatment equipment. They're not exciting. Nobody thinks about them. That's exactly the problem, according to the advisory. Operators often don't even know which of their PLCs are connected to the internet, especially when a vendor or contractor installed a remote-access modem years ago and never told anyone.

The agencies said the sectors most exposed are Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. That's most of the stuff that keeps a country running.

How the attackers are doing it

According to isssource and Infosecurity Magazine, which both reviewed the advisory, hackers are using commercial internet-scanning services like Censys and ZoomEye to find Siemens S7 PLCs sitting exposed online with outdated software. Once they find a target, AI-assisted scripts probe for known vulnerabilities.

The attackers are also leaning on open-source industrial automation libraries, specifically snap7.dll and python-snap7, combined with AI scripting to build custom tools that mimic real OT monitoring software. Those tools can read and write to a PLC's memory, configuration data, and ladder logic, the actual code that tells the equipment what to do, using the S7comm protocol.

CISA's own summary is blunt: "This is not a theoretical risk, it is an active threat." The agency says successful exploitation could disrupt industrial processes, cause safety incidents, damage equipment, or trigger cascading failures across connected systems.

The advisory's top mitigation is simple and depressing: take these things off the internet. Inventory every S7 PLC, apply security patches, kill outside network access, tighten authentication, and watch for anomalies.

The Minnesota attacks that preceded this

This advisory didn't come out of nowhere. It follows a coordinated cyberattack on more than 30 Minnesota water systems over the weekend of Sunday, July 26 and Monday, July 27, according to Minnesota IT Services (MNIT), which activated its emergency cybersecurity response immediately.

In Braham, Minnesota, self-styled the "Homemade Pie Capital of Minnesota," city officials said their water plant went offline for an unknown reason around 9:30 a.m. on July 27. It was back up within two hours, according to the Epoch Times.

Fox News reported the disruption ultimately reached water or wastewater utilities in at least seven states, citing FBI statements that "some of that activity degraded water operations." State officials said there were no active requests for residents to change their water usage, meaning the disruptions were operational and technical, not a threat to the water supply itself.

CISA's July 30 alert, issued in the immediate aftermath, told water systems to check equipment made by Rockwell Automation, Schneider Electric, and Siemens, and warned that hackers had been changing operator passwords and altering IP addresses to lock utilities out of their own systems, forcing some to boil-water notices and manual operations.

The Iran question, still unresolved

Multiple outlets, including Breitbart citing ABC News and the New York Times, reported that U.S. officials believe the Minnesota attacks may have Iranian connections. That's a real and serious possibility given Iran's documented history of targeting U.S. water infrastructure.

But it's still unproven. Breitbart's own reporting noted that officials were explicit the assessment is preliminary and no formal attribution has been made pending forensic analysis. John Israel, Minnesota's chief information security officer, said the state handed its findings to the federal government, which is evaluating the activity "in the broader national context" and leading the effort to determine attribution. The FBI has acknowledged the intrusions but has not publicly named a responsible party.

Tenable, a cybersecurity firm cited by the Epoch Times, floated a theory linking the Minnesota attack to the broader Iran conflict, but that's an outside analyst's theory, not a government determination. Readers should treat the Iran link as a live investigative lead, not a confirmed fact, until CISA, the FBI, or another named federal authority says otherwise on the record.

What's actually new here

The August 19 advisory is notably not just a rehash of the Minnesota incident. Infosecurity Magazine and isssource both flag that the use of AI to generate exploitation scripts is described by the authoring agencies as "an evolution in threat actor capabilities." This isn't only about Iran or only about Minnesota. It's a broader warning that AI has lowered the skill floor for attacking industrial control systems generally, across whichever nation-state or criminal group decides to use it next.

The unresolved question is basic and uncomfortable: the United States has close to 170,000 drinking water and wastewater systems, according to Fox News, many of them small operations connecting physical equipment to internet-enabled technology so workers can monitor facilities remotely. How many of those systems actually have the money or staff to rip their PLCs off the internet the way CISA is now telling them to remains an open question.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

right
Fox NewsWater cyberattack hits at least 7 states
right
Epoch TimesFeds Issue Warning About Hackers Targeting Water Systems
right
BreitbartFeds Warn Water Systems of Rising Cyber Threats Following Minnesota Attacks
unknown
cisaDefending Against an Active Threat to Siemens S7 Series PLCs
unknown
isssourceSiemens PLC a Threat Target: Feds
unknown
infosecurity-magazineICS Operators Warned of AI-Driven Attacks on Siemens PLCs