Five U.S. agencies, including the NSA, CISA, and the FBI, issued a joint warning this week about hackers using AI to build working attack tools against Siemens industrial controllers, the small computers that run pumps, valves, and machinery inside factories, power plants, and water systems.
The agencies did not call this a future risk. They called it an active threat happening right now, aimed at devices in manufacturing, energy, water, chemical, and food production.
Here is what makes this different from a normal hacking story. The attackers are combining open industrial-automation code with AI-assisted scripting to build tools that look like legitimate monitoring software but actually read and rewrite the logic inside the controller. Building tools like this used to take deep, specialized knowledge of industrial systems. AI now does much of that work, which means an attacker no longer needs years of training to try it.
This warning did not appear out of nowhere. It builds on an advisory first issued in April, which described an Iran-linked hacking group breaking into a different brand of industrial controller, made by Rockwell Automation. That warning was expanded in July to add Schneider Electric equipment, and now Siemens. The pattern is a group moving from one equipment brand to the next, and AI appears to be speeding up how fast they can adapt to each new target.
The stakes are not theoretical. In late July, a coordinated attack hit more than 30 community water and wastewater systems across Minnesota over two nights, temporarily shutting down one city's treatment plant and forcing others to disconnect automated equipment. Security researchers tied the attack to the same Iran-affiliated group named in the earlier advisories.
There is one honest limit to this story. The UK's AI Security Institute ran tests to see whether AI models could hack this kind of physical equipment entirely on their own. They could not. The models kept getting stuck on the ordinary office computer networks sitting in front of the industrial equipment, not the equipment itself. So AI has not yet closed the full loop from "read about a vulnerability" to "take down a power plant" without human help.
What AI has done is remove the biggest barrier that used to protect these systems: scarcity of skilled attackers. Writing a working exploit against industrial equipment used to require rare expertise. Now it requires a decent AI model and public information about the target, both of which are cheap and available. Separate research this year found that internet-exposed industrial devices grew by roughly 40 percent between 2024 and 2025, giving attackers more targets right as the skill required to hit them keeps dropping.
For any business running internet-connected machinery, whether that is a factory line, a warehouse, or a water pump, the practical takeaway is simple. The equipment quietly connected to the internet for remote monitoring is now a real front door. Getting it off the open internet, or at minimum checking with whoever manages it, is no longer a task that can wait for the next IT budget cycle.