"All S7s" Targeted: AI-Driven Changes the Economics of Attacks and a Warning for Water Infrastructure
On August 20th, multiple government agencies, including the US Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the NSA, issued a joint warning. The warning stated that attackers were targeting Siemens' S7 series industrial control devices, and that the damage had already affected water facilities in more than 12 states across the US. What's noteworthy for engineers is not the scale of the damage itself, but the fact that this warning was issued within the context of "AI changing the economics of attacks."
An Unusually Broad Warning Scope: "All S7s"
What's distinctive about this warning is its broad scope. CISA explicitly states that it targets "all" Siemens S7 series PLCs (Programmable Logic Controllers, specialized computers that automatically control machinery in factories and facilities), used to control automated physical processes in a wide range of sectors, including water, energy, manufacturing, and agriculture. This is a broader alert than usual, indicating that the entire product family is being targeted, rather than a warning focused on a specific model number or vulnerability.
Confirmed damages include decreased water pressure, flooding, recommendations for boiling water for disinfection, and cases where users were forced to switch from automated to manual control. These demonstrate that cyberattacks are not merely abstract events in the world of data, but are actually having physical consequences that affect people's daily lives.
Agent-Based AI Changing the "Economics of Attacks"
This news is more significant than a single vulnerability report because it is part of a larger trend: agent-based AI is changing the very nature of cyberattacks.
Traditional cyberattacks, while using scripts and automated vulnerability scanners, have historically relied on human operators for critical decision-making. However, with the advent of agent-based AI (AI systems capable of autonomously performing multiple tasks), a "feedback loop" is theoretically becoming possible, where multiple AI systems share tasks, analyze each other's findings, and continue attacks with limited human intervention. If this actually works, relatively small groups could launch simultaneous attacks against a large number of targets at machine-like speeds, potentially fundamentally changing the very "economics" of cybercrime and state-sponsored espionage.
The Issue of "Attribution Difficulty": A Matter to Handle Calmly
However, caution is necessary when evaluating such discourse on "autonomous AI attacks." Technically identifying who carried out the attack—"attribution"—remains an extremely difficult task, and the claim that "this was an AI-driven attack" itself requires careful scrutiny.
In fact, the "International AI Safety Report 2026," compiled by an international group of experts, offers a calm assessment of this point. In November 2025, an AI development company reported a case where a threat actor used its model to automate 80-90% of the intrusion activity, with human involvement limited to critical decision-making points. The researchers have also demonstrated that AI systems can autonomously search for vulnerabilities in computer networks in laboratory environments. However, the report also notes that there have been no reported instances of general-purpose AI systems executing fully autonomous end-to-end cyberattacks in the real world.
The Counter-Movement: "Defenders Also Use AI"
In parallel with the CISA and other warnings, it's important to note that not only attackers but also defenders are beginning to utilize AI. This means a new form of competition is emerging, where both attackers and defenders are increasingly facing off against each other with automated systems.
The proliferation of AI-powered monitoring and detection systems to protect critical infrastructure, such as OpenAI's defender model "GPT-5.6-Cyber," which we previously discussed, and the issues raised in this warning, can be seen as part of this trend of "automated defense."
What Engineers Should Consider
This joint government warning is significant because it links the abstract discussion of "AI risk" to concrete damage that is actually impacting people's lives. CISA is urging potentially affected businesses to patch affected software, isolate controllers exposed to the internet, secure remote access, and refresh outdated credentials.
For organizations operating industrial control systems, this warning should be viewed not only as preparation for the future risk of "automated AI attacks," but also as an opportunity to address the immediate challenge of "a lack of basic security hygiene" that is already underway. Before discussing the sophistication of attacks, the most basic and effective first step is likely to be ensuring that their control systems are not vulnerable to the internet.