Three US federal agencies said on 19 August that hackers are now using AI to write the exploit code aimed at industrial controllers running America’s water, energy and manufacturing plants. The joint advisory from CISA, the FBI and the National Security Agency followed a documented attack on more than 30 community water utilities in Minnesota over 26 and 27 July, and it treats the AI involvement as the part of the pattern worth flagging, rather than the intrusions themselves.
The mechanism is mundane by design. Threat actors scan the internet for Siemens S7 controllers left exposed with default or weak credentials, then use AI assisted scripting built on the open source snap7 library to read and write to the controller’s memory over the S7comm protocol. None of the individual steps is new to industrial control security. What AI changes is the labour: a working exploit against an exposed device no longer requires anyone to write it by hand.
The advisory stops short of naming a culprit, calling them only threat actors. That restraint sits awkwardly next to the pattern already on record. CISA had linked Iranian affiliated actors to similar intrusions against Rockwell Automation controllers in April, and the July attacks on Minnesota carry hallmarks researchers have tied to the group CyberAv3ngers. The agencies appear to know more than the document commits to in writing.
What the advisory does not resolve is scope. It documents Minnesota in detail and describes the technique as active more broadly, without a state by state count or a total of affected utilities. Coverage of the advisory has put the states involved anywhere from a handful to more than a dozen, a detail a formal accounting would have settled, and this one has not.



