
Hackers are using AI to find and exploit the devices that control America’s water supply. That’s not a hypothetical. It’s happening now, and federal agencies are alarmed enough to issue a joint warning about it.
According to TechCrunch, CISA, the FBI, and the National Security Agency have put out an advisory warning that hackers are actively targeting Siemens S7 programmable logic controllers, the devices that automate physical processes in water systems, energy plants, manufacturing, and agriculture. The agencies say “all” Siemens S7 devices are being targeted, which is about as broad a threat scope as you can get.
What makes this warning different from the usual government boilerplate is the AI angle. The attackers are using AI tools to generate exploit scripts based on publicly available information. They’re scanning for programmable logic controllers running outdated software, and they’re using AI to understand how those devices actually work. An incident response professional who works with critical infrastructure told TechCrunch this part is noteworthy. But he also pointed out that these devices were already dangerously vulnerable before AI entered the picture. So the AI isn’t creating a new problem so much as accelerating an old one.
The consequences of a successful attack aren’t abstract. CISA says disruptions could cause downtime, safety incidents, or physical equipment damage. In the context of water treatment, that means communities could lose access to clean water, or worse, hazardous processes could go wrong. These aren’t IT systems. They control real physical infrastructure.
The pattern here is worth paying attention to. This is the latest in a string of warnings following suspected Iranian hacker activity targeting U.S. water suppliers and wastewater providers. Officials have confirmed intrusions at water facilities across Minnesota, Michigan, Arkansas, Georgia, and New Jersey. The attacks have been escalating since Iranian-linked groups first went after internet-connected critical infrastructure systems.
CISA has been telling critical infrastructure operators for years to keep these devices off the public internet. The fact that it keeps repeating this advice tells you how well that message has landed. Rural communities are especially exposed because their water systems cover large geographic areas and often lack the IT resources of larger municipalities. They’re the most vulnerable and, historically, the least equipped to defend themselves.
The AI piece is a signal that the barrier to entry for these attacks is dropping. You no longer need deep technical knowledge of industrial control systems to probe for weaknesses. If an AI tool can do the reconnaissance and write the exploit, that opens the door to a wider range of attackers. That should worry anyone who drinks tap water.