Hackers Are Using AI to Target Factory Systems | Sync Up
Cyberattacks don’t always end with stolen files or a locked computer. Federal agencies are warning that hackers are using AI-generated code to target the systems that control factory equipment, and we’ll explain what that could mean for manufacturers as we sit down and sync up with Rocket IT’s weekly technology update.
In this episode, you’ll learn more about:
- How attackers are using AI-generated code to target factory control systems.
- Why PLCs play such an important role in keeping physical equipment running.
- What federal agencies have observed and why the threat is still developing.
- How compromised controllers could disrupt production, damage equipment, or create safety concerns.
- Which security gaps can leave factory systems exposed to attackers.
- What manufacturers can do to better protect equipment, networks, and remote access.
Video Transcript
On a factory floor, a computer problem can become a production problem very quickly. Many of the devices that tell equipment when to start, stop, open, close, heat, cool, or move are called programmable logic controllers, or PLCs. They turn digital instructions into physical action.
A group of federal agencies, including CISA, the FBI, and the NSA, issued a joint warning about an active threat targeting Siemens S7 Series PLCs. These controllers are used in manufacturing and also appear in energy, water, chemical processing, food production, and other facilities where digital systems manage physical operations.
The AI part is important, but not because an autonomous system is taking over a plant. According to the advisory, attackers are using AI to generate and refine exploitation scripts from publicly available information. That can reduce the skill and time needed to create tools that find exposed controllers, test known weaknesses, and disguise malicious activity as legitimate monitoring software.
The activity described in the warning is mainly reconnaissance and capability development. In plain English, the attackers are learning how these systems are configured and testing whether they can read from or write to them. Because PLCs control physical processes, unauthorized changes could interrupt production, affect product quality, damage equipment, or create safety concerns.
The advisory doesn’t say factories across the country are already being shut down at scale. It says attackers are building and testing capabilities against exposed systems, which gives organizations a chance to reduce the risk before that activity turns into disruption.
The weak point isn’t AI by itself. Federal agencies say the attackers are looking for controllers that are exposed to the internet, running outdated software, poorly protected, or not properly separated from other networks. In some cases, remote access provided to vendors or system integrators may also create exposure the business doesn’t realize is there.
For manufacturers, the first move is visibility. Know which controllers are in the environment, which software versions they’re running, and whether any of them can be reached from outside trusted networks.
From there, keep operational systems off the public internet wherever possible and separate them from ordinary business systems. Remote access should be limited to the people and devices that actually need it, protected with strong authentication, and reviewed regularly.
Organizations should also apply relevant updates and monitor for unusual connections, unexpected configuration changes, or activity happening outside approved maintenance windows. If a third party maintains the equipment, confirm how that company connects and who’s responsible for monitoring its access.
The larger lesson is that AI isn’t replacing the fundamentals of cybersecurity. It’s making it faster and easier to take advantage of systems that were already exposed, outdated, or misconfigured. For manufacturers, the answer is to close those openings before attackers can move from testing to disruption.
For help, contact Rocket IT using the link in this video’s description. And to stay up to date on trending technology news, hit that subscribe button and the bell to catch us on next week’s episode of Sync Up with Rocket IT.
Related Posts
Subscribe to Rocket IT's Newsletter
Stay up to date on trending technology news and important updates.
Find out if Rocket IT is the right partner for your team
Claim a free consultation with a technology expert.