What is the Attack? U.S. cybersecurity agencies, including CISA, NSA, FBI, DOE, and EPA, have warned of an active cyber threat targeting Siemens S7 Series PLCs that are Internet-exposed, running outdated software, or otherwise inadequately protected. The advisory highlights activity involving reconnaissance and unauthorized interaction with PLCs, including scanning of Internet-accessible industrial systems. Successful access to PLCs could allow threat actors to modify industrial processes, disrupt operations, manipulate control logic, introduce safety hazards and cause physical damage. Organizations operating Siemens S7 Series PLCs should immediately assess Internet exposure, network segmentation, access controls, monitoring, and PLC-specific security configurations. What is the recommended Mitigation? 1. Inventory Siemens S7 Series PLCs: • Identify all Siemens S7 Series PLCs within the environment. • Identify firmware versions and device details. • Determine which PLCs are reachable from untrusted or external networks. • Use FortiGuard Operational Technology Security Service (OTSS) for OT asset discovery and device identification. 2. Verify Network Segmentation: • Ensure Siemens S7 PLCs are not directly accessible from the Internet. • Restrict access to S7 communications, including TCP/102, to authorized systems. • Segment OT networks from enterprise and corporate networks. • Use DMZ architectures where communication between IT and OT is required. • Restrict routing between untrusted networks and PLC environments. • Apply appropriate controls to historian and monitoring communications to limit unauthorized write access. FortiOS and FortiGate can enforce network segmentation, routing restrictions, and policy-based access controls, while OTSS provides OT-aware visibility and monitoring. 3. Strengthen Access Controls: • Restrict PLC access to authorized engineering workstations and management systems. • Use network access policies rather than relying solely on PLC IP/MAC allowlisting. • Apply application controls to engineering workstations using FortiEDR. • Require MFA for remote access to OT environments using FortiPAM and/or FortiGate. • Minimize remote administrative access to PLCs and engineering systems. 4. Enable Comprehensive OT Monitoring and Logging: Monitor for: • Unauthorized S7 connections to PLCs. • Unexpected S7 PUT/GET operations. • Unauthorized PLC configuration or program changes. • IP scanning and reconnaissance activity. • S7 protocol scanning and enumeration. • Unexpected communication with PLCs from enterprise or external networks. FortiGuard OTSS provides OT-aware visibility and monitoring, while FortiGate/FortiGuard IPS can detect and block network activity targeting S7 services and protocols, including S7 scanning and enumeration activity. 5. Implement S7-Specific Hardening: • Restrict access to PLC web interfaces and disable unnecessary services where supported. • Disable unused protocols and services. • Limit S7 communications to required source and destination systems. • Review PLC security settings and engineering workstation configurations. • Validate PLC programs, configurations, firmware, and logic for unauthorized changes. What FortiGuard Coverage is available? • FortiGuard Operational Technology Security Service (OTSS) – Provides OT asset discovery, device identification, protocol-aware monitoring, and security visibility for industrial environments, including Siemens S7 infrastructure. FortiGuard Labs • FortiGate / FortiOS – Enforces network segmentation, access-control policies, routing restrictions, and controlled connectivity between enterprise, DMZ, and OT environments. • FortiGuard IPS – Detects and blocks network-based attacks, scanning, enumeration, and suspicious activity targeting industrial protocols and services, including Siemens S7 communications. • FortiEDR – Protects engineering workstations against malicious applications and unauthorized activity that could be used to compromise OT environments. • FortiPAM – Provides privileged access management and supports stronger controls, including MFA, for administrative and remote access to critical systems. • FortiGuard Network Detection and Response (NDR) – Provides additional network visibility and behavioral detection to identify anomalous activity within OT and IT environments. • FortiGuard Incident Response – Supports investigation, containment, and recovery following suspected compromise of PLCs or OT infrastructure.
A multi-agency advisory warns of active cyberattacks targeting Internet-exposed Siemens S7 Series PLCs via reconnaissance scanning and unauthorized S7 protocol access. Successful compromise allows threat actors to modify control logic, disrupt operations, and cause physical damage. Mitigations include removing Internet exposure, enforcing strict network segmentation for OT assets, restricting access to S7 communications (TCP/102), and implementing comprehensive OT monitoring for unauthorized connections and configuration changes.