Skip to main content
Critical InfrastructureThreat AdvisoryAug 22, 2026, 1:55 PM· 4 min read· in defense security

U.S. Agencies Warn Iran-Linked Hackers Are Using AI-Generated Exploits to Target Water Systems Across 12 States

Federal authorities have issued a joint advisory warning that suspected Iranian threat actors are deploying AI-generated scripts to compromise Siemens programmable logic controllers at U.S. water utilities.

By Miguel Carvalho

Federal Security Agencies 40%Municipal Water Operators 30%Cybersecurity Analysts 30%
Federal Security Agencies
Focus on the systemic threat posed by AI-enabled exploitation of critical infrastructure.
Municipal Water Operators
Focus on operational resilience and the effectiveness of manual overrides in preventing physical harm.
Cybersecurity Analysts
Focus on the underlying security failures that allow automated exploits to succeed.

Why it matters

The integration of artificial intelligence into industrial cyberattacks dramatically lowers the technical expertise required to disrupt critical infrastructure. This evolution places thousands of poorly secured municipal water and energy facilities at immediate risk of operational interference.

In late July, operators at a municipal water facility in Clayton County, Georgia, watched their automated monitoring systems unexpectedly go offline. The disruption forced a sudden shift to manual controls and triggered a precautionary boil-water advisory for 300,000 residents as pressure levels fluctuated across the network. The incident in Georgia was not an isolated mechanical failure. By mid-August, federal authorities confirmed that water and wastewater utilities across at least 12 states—including Minnesota, Michigan, South Dakota, and New Jersey—had experienced similar coordinated disruptions to their operational technology.[1][2]

The underlying mechanism driving these incidents was detailed on August 19, when a coalition of five U.S. agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency, issued a joint advisory. The campaign specifically targets internet-exposed Siemens S7 Series programmable logic controllers (PLCs). These industrial computers serve as the critical nodes responsible for regulating physical processes across municipal infrastructure, translating digital commands into physical actions such as valve operation, water pressure regulation, and chemical treatment.[3][4][5]

What distinguishes this campaign from previous infrastructure probes is the integration of artificial intelligence into the attack chain. The federal advisory notes that threat actors are deploying AI-generated exploitation scripts that are carefully disguised as legitimate operational technology monitoring software. Rather than manually crafting custom malware for each target, the attackers are utilizing AI to rapidly generate code capable of gaining initial access, pilfering credentials, and executing denial-of-service commands against the controllers. This approach allows the threat actors to scale their operations across multiple facilities simultaneously.[3][5][7]

The cyber campaign specifically targets internet-exposed Siemens S7 Series programmable logic controllers used to regulate physical processes.

Historically, compromising a Siemens S7 controller required deep, specialized engineering knowledge of proprietary industrial protocols. By pairing AI-assisted scripting with open-source automation libraries, the attackers have fundamentally altered the required capability threshold. The AI tools automate the generation of code that can read and rewrite PLC memory and ladder logic, effectively bypassing the need for decades of specialized operational technology experience. This industrialization of exploit development means that less-skilled adversaries can now execute complex attacks that were previously the exclusive domain of elite state-sponsored hacking teams.[3][4][5]

Historically, compromising a Siemens S7 controller required deep, specialized engineering knowledge of proprietary industrial protocols.

While the federal advisory did not formally attribute the activity to a specific nation-state, multiple intelligence sources and cybersecurity experts have linked the campaign to Iran-nexus threat actors. This attribution aligns with a documented, multi-year pattern of Iranian operations targeting the U.S. water sector. In late 2023, the Islamic Revolutionary Guard Corps-linked group known as CyberAv3ngers executed a similar campaign against water facilities in Pennsylvania, compromising Israeli-made programmable logic controllers to force operators into manual control modes.[1][2][6]

The success of the current campaign relies less on sophisticated zero-day exploits than on systemic architectural weaknesses within municipal infrastructure. Attackers are utilizing automated internet scanning services, such as Censys and ZoomEye, to locate programmable logic controllers that are directly connected to the public internet. These exposed devices frequently operate with outdated software, lack basic firewall protections, or rely on default passwords, providing the AI-generated scripts with an unobstructed pathway into the facility's operational technology network.[3][4][5][6][7]

Facility operators have successfully prevented contamination by severing network connections and reverting to manual overrides.

Despite the geographic breadth of the targeting, the physical consequences of the cyberattacks have remained strictly contained. No drinking water contamination has been reported in any of the affected states. Facility operators have successfully maintained system safety by severing network connections and reverting to manual overrides when digital interfaces are compromised. This resilience highlights a critical defense mechanism within the water sector: the ability of human operators to physically decouple mechanical processes from compromised digital networks before safety parameters are breached.[1][2][6]

The deployment of AI-generated scripts against industrial control systems represents a structural shift in operational technology risk that extends far beyond the water sector. Federal agencies are now directing critical infrastructure operators across the manufacturing, energy, and chemical sectors to immediately isolate all programmable logic controllers from the internet. The convergence of known vulnerabilities, accessible open-source exploitation libraries, and AI-assisted development creates a highly probable attack vector for any inadequately protected facility, necessitating a fundamental reevaluation of how municipal infrastructure is secured.[3][4][5][7]

What to know

  1. Suspected Iran-linked hackers have targeted water and wastewater systems in at least 12 U.S. states.
  2. A joint federal advisory warns attackers are using AI-generated scripts to exploit Siemens S7 Series controllers.
  3. The use of AI dramatically lowers the technical expertise required to manipulate industrial operational technology.
  4. Attackers are utilizing automated scanning services to find internet-exposed controllers with outdated software.
  5. No drinking water contamination has occurred, as operators have successfully reverted to manual controls.

Where opinion splits

Federal Security Agencies

U.S. cyber authorities view the campaign as a dangerous evolution in threat actor capabilities.

Agencies including CISA and the NSA emphasize that the use of artificial intelligence to generate exploitation scripts fundamentally changes the risk landscape for industrial control systems. By automating the creation of code that can manipulate proprietary protocols, attackers no longer need years of specialized engineering experience. Officials argue this necessitates an immediate, sector-wide push to disconnect all critical programmable logic controllers from the public internet.

Municipal Water Operators

Local utility managers emphasize the practical resilience of their facilities against digital intrusion.

While acknowledging the disruption to automated monitoring, facility operators point out that the cyberattacks have failed to achieve their presumed primary objective: compromising public safety. Utilities have relied on established contingency protocols, successfully maintaining water pressure and preventing contamination by physically severing network connections and operating pumps and valves via manual overrides.

Cybersecurity Analysts

Security researchers argue the root cause is poor basic hygiene rather than advanced AI.

Industry analysts note that while the use of AI-generated scripts is novel, the attacks are only successful because of systemic architectural failures across the municipal sector. They point out that the targeted controllers are often left directly exposed to the internet without basic firewall protections or updated software, making them vulnerable to even rudimentary automated scanning tools.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

Federal Security Agencies 40%Municipal Water Operators 30%Cybersecurity Analysts 30%
  1. [1]The RecordMunicipal Water Operators

    Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents

    Read on The Record
  2. [2]CBS NewsMunicipal Water Operators

    At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say

    Read on CBS News
  3. [3]CISAFederal Security Agencies

    Defending Against an Active Threat to Siemens S7 Series PLCs

    Read on CISA
  4. [4]CyberScoopFederal Security Agencies

    Hackers target Siemens PLCs using AI-generated scripts, US warns

    Read on CyberScoop
  5. [5]The Hacker NewsFederal Security Agencies

    U.S. Warns of AI-Generated Exploits Targeting Siemens PLCs in Critical Sectors

    Read on The Hacker News
  6. [6]CSISCybersecurity Analysts

    Geographic Distribution of Attacks

    Read on CSIS
  7. [7]Cybersecurity DiveCybersecurity Analysts

    AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn

    Read on Cybersecurity Dive

Comments

Stay informed

Every angle. Every day.

Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.