Construction AI BriefSubscribe →
Issue
№193
Pillar
Trend
Audience
Trade sub
Dated
2026.08.21

The NSA and CISA say AI is writing exploits for the same controllers your electrical sub commissions

A joint federal advisory says hackers are using AI coding assistants to build exploit scripts for Siemens S7 PLCs — the controllers electrical and controls subs install and commission on water, energy, and manufacturing jobs, often before the network is locked down.

ByConstruction AI BriefAbout this publication

The NSA, CISA, FBI, DOE, and EPA issued a joint advisory on August 19, 2026, warning that hackers are using AI coding assistants to build exploitation scripts for Siemens S7 Series programmable logic controllers — the same controllers electrical and controls subs rack, wire, and commission on water treatment, energy, manufacturing, and building-automation jobs. The advisory, AA26-231A, calls it "not a theoretical risk" but an active threat.

What's actually being targeted?

Siemens S7 Series PLCs — the workhorse controllers behind pumps, valves, process lines, and building automation systems across six sectors the advisory names explicitly: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. That last category covers a lot of ground a GC or MEP sub touches directly: office towers, hospitals, data centers, and any commercial building with a modern BAS.

Attackers are combining two things that used to require real engineering skill: internet scanning services like Censys and ZoomEye to find S7 PLCs that are exposed or poorly segmented, and open-source industrial automation libraries (snap7.dll, python-snap7) fed into AI coding assistants to generate custom exploit and reconnaissance tools — some disguised as legitimate monitoring software. CISA's language is blunt about why that matters: AI "dramatically reduces the technical expertise and time required to develop working ICS exploitation scripts."

This isn't a brand-new campaign. CISA's earlier advisory, AA26-097A, had already tied PLC targeting at US water and energy utilities to CyberAv3ngers, an Iran-linked group. AA26-231A is the update confirming the attackers are now using AI to write the scripts themselves.

Why does this land on a construction company, not just the plant operator?

Because a PLC's most exposed moment is often before the ribbon-cutting, not after. During construction and commissioning, controllers get energized on temporary or partially built networks, remote-accessed by the vendor's start-up tech, and left with factory-default or shared commissioning credentials while punch-list items get closed out. Final network segmentation and credential hardening are frequently a closeout task — which means the exposure window CISA is describing overlaps directly with the period when a controls sub, not the owner's IT department, has hands on the hardware.

Who touches the riskWhat they're doing when it matters
Controls / instrumentation subProgramming, energizing, and commissioning S7 PLCs
Electrical subWiring PLC network drops, sometimes before segmentation is final
BAS/controls integratorInstalling "monitoring" software and remote-access tools during startup
GC's commissioning agentCoordinating punch-list access windows that can leave systems reachable
Owner's IT/OT security teamOften not engaged until substantial completion

What should a sub actually do differently?

CISA's mitigation list, translated to a construction-phase checklist:

  • Inventory every S7 PLC on the job before it's powered up — model, firmware version, network location.
  • Change default and commissioning-shared credentials before energization, not at closeout.
  • Never leave commissioning remote access open to the public internet, even temporarily during a punch-list window.
  • Vet any third-party monitoring or diagnostic software before installing it on an OT network — the advisory specifically flags AI-generated tools disguised as legitimate monitoring utilities.
  • Loop in the owner's network team during rough-in, not at substantial completion, so segmentation is real before the system goes live rather than a closeout checkbox.

None of this requires new software or a security vendor. It requires treating the commissioning window the way CISA is now telling utilities to treat production: as the period the controller is actually exposed.

The takeaway

If your firm installs, wires, or commissions Siemens S7 controllers — water, energy, manufacturing, or a commercial building's BAS — this advisory is describing your jobsite during startup, not just the owner's network after handover. Pull your commissioning procedure this week and check it against CISA's five items above; the fix is a process change, not a purchase.

Construction AI Brief has previously covered how AI is lowering the skill bar for attackers targeting construction generally — this advisory is the first time a federal agency has named the specific hardware a controls sub touches on the job.

Construction AI Brief publishes new coverage on AI in commercial construction three times a week. Subscribe at constructionaibrief.com.

FAQCommon questions
What did CISA's August 19, 2026 advisory (AA26-231A) actually say?
The NSA, CISA, FBI, DOE, and EPA jointly warned that threat actors are using AI coding assistants to generate exploitation scripts targeting Siemens S7 Series programmable logic controllers, disguising the tools as legitimate monitoring software. The advisory names Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities as the sectors most targeted.
How are attackers finding vulnerable PLCs?
By running internet scanning services such as Censys and ZoomEye to locate Siemens S7 PLCs that are exposed online or not properly segmented from other networks, then combining open-source industrial automation libraries (snap7.dll, python-snap7) with AI coding assistants to build custom exploitation and reconnaissance tools.
Is this connected to earlier Siemens PLC attack warnings?
Yes. CISA's April 2026 advisory (AA26-097A) had already attributed PLC targeting at water and energy utilities to an Iran-linked group publicly known as CyberAv3ngers. AA26-231A is the update that confirms attackers are now using AI to generate the exploitation scripts themselves, which the agencies call an evolution in capability, not a new campaign.
Does this apply during construction, or only after a building is operating?
It applies during construction and commissioning too. PLCs are frequently energized, temporarily networked, and remote-accessed for testing before final network segmentation and credential hardening happen at closeout — which is exactly the exposure window CISA describes. A controls sub commissioning a pump station or a manufacturing line is handling the hardware this advisory is about, often before the owner's cybersecurity team has taken over.
What should a controls or electrical sub do this week?
Inventory every Siemens S7 PLC on the job before it goes live, change default and vendor-set credentials before energization, don't leave commissioning remote access open to the internet, and treat any third-party 'monitoring tool' offered for installation on the OT network as unverified until IT confirms it. Then coordinate segmentation with the owner's network team from day one instead of at handover.
End of sheet — issue №193
Published · 2026.08.21
Project
Construction AI Brief
Dated
2026.09.07
Sheet
1 / 1
Rev
A
Published independently · constructionaibrief.com · © 2026Facebook·Privacy·About