Skip to content
Modat Try Magnify
← Back to Blog
Research 20 Aug 2026

Thousands of Siemens PLCs Are Listening. So Are Threat Actors.

NSA, CISA, FBI, DOE and EPA issued a rare joint advisory on 19 August 2026: threat actors are using AI-generated code to attack Siemens S7 Series programmable logic controllers at water treatment plants, power facilities and chemical sites. The next day, Modat Magnify identified 7,435 internet-exposed S7 services across 77 countries, every one answering on TCP port 102, and six of them fail-safe safety controllers.

Thousands of Siemens PLCs Are Listening. So Are Threat Actors.

On 19 August 2026, NSA, CISA, FBI, DOE and EPA issued a rare joint advisory, AA26-231A: threat actors are using AI-generated code to attack Siemens S7 Series programmable logic controllers at water treatment plants, power facilities, chemical plants and manufacturing sites. Its first recommendation is to take any S7 PLC reachable on public port 102 offline immediately.

The next day, Modat Magnify identified 7,435 Siemens SIMATIC S7 services answering on the public internet, across 77 countries.

What the Advisory Describes

Actors locate exposed Siemens PLCs, then use AI to generate Python exploitation scripts built on the open-source python-snap7 wrapper (source) and the Snap7 library it binds to, distributed as snap7.dll on Windows. Both are legitimate industrial communication libraries used daily by integrators. What changed is the cost of using them.

The chain runs in five stages: reconnaissance (T1596.005) locating port 102 and fingerprinting firmware; capability development (T1587.004, T1588.007) using AI to write exploit code against the versions found; access (T0834) over S7comm; masquerade (T0849), disguising the tooling as OT monitoring software; and impact (T0893, T0821), reading and writing PLC memory, modifying ladder logic and altering physical process control.

The advisory names no CVEs and defers to Siemens ProductCERT. It states the campaign has already reached capability development.

7,435 Services on One Port

All 7,435 records were active on 20 August 2026, and every one answers on TCP port 102, the S7comm protocol AA26-231A names. Of the total, 6,268 return a full banner with module and firmware detail; 1,132 answer the S7comm handshake but expose nothing further.

The advisory’s first mitigation is to remove S7 PLCs from the public internet. 7,435 of them answered the day after it was published.

Where They Are

JP1,257
TR1,025
RO591
CN499
ES485
IT483
US362
GR302
DE289
SI248
VN219
LT216
PL192
CZ101
FR97
BE94
BY86
AT72
BR69
NL49
HR42
SK40
TW38
CA35
DK30
RU29
PT28
SE26
FI24
HU23
EE22
TH21
AU · GB · AR20
IN · GE19
IL · UA · MY17
SG · IR · IS16
RS13
CH12
HK11
MA10
BG9
PS8
LV7
KR · PA6
KZ · ID5
PR4
AE · ZA · NO · MX · KG · JO · HN · EG · CY · CL · BD3
NZ · LB · KH · AL2
PH · PE · MT · IE · IQ · FO · AZ1

Figure 1: All 77 countries with an exposed S7 service on port 102, by count.

Japan and Türkiye account for 31% of the total, 2,282 of 7,435. Romania at 591 exceeds both the United States (362) and Germany (289).

Who Carries Them

AS4685 (Asahi Net)1,084
AS16135 (Turkcell)674
AS12302 (Vodafone Romania)560
AS3329 (Vodafone Greece)273
AS6167 (Verizon Business)236
AS3352 (Telefónica España)221
AS15897 (Vodafone Türkiye)220
AS3320 (Deutsche Telekom)217
AS5603 (Telekom Slovenije)191
AS4837 (China Unicom China169)172
AS13194 (UAB Bite Lietuva)141
AS200845 (Avatel Telecom)135
AS45899 (VNPT Corp)122
AS4134 (ChinaNet)113
AS20978 (TT Mobil)103
AS2514 (NTT PC Communications)100
AS30722 (Fastweb)93
AS9808 (China Mobile Communications)77
AS42772 (Unitary Enterprise A1)69
AS7552 (Viettel Group)58
AS21928 (T-Mobile USA)55
AS3215 (Orange)54
AS13036 (T-Mobile Czech Republic)53
AS3269 (TIM)51
AS16232 (TIM)51
AS12430 (Vodafone Spain)45
AS8374 (Polkomtel)44
AS5432 (Proximus)41
AS1257 (Tele2 SWIPnet)40
AS8764 (Telia Lietuva)38
AS6848 (Telenet)38
AS132525 (HeiLongJiang Mobile)34
AS29314 (Vectra)33
AS21283 (A1 Slovenija)31
AS17511 (OPTAGE)31
AS5617 (Orange Polska)30
AS1267 (Wind Tre)30
AS12479 (Orange Espagne)29
AS8447 (Telekom Austria)28
AS5391 (Hrvatski Telekom)26
AS12912 (T-Mobile Polska)26
AS57558 (Metis)25
AS35612 (EOLO)25
AS577 (Bell Canada)21
AS6855 (Slovak Telekom)20
AS3212 (Telemach Slovenija)20
AS17421 (Mobile Business Group)20
AS18403 (FPT Telecom)19
AS1136 (KPN)19
AS42082 (JSC Silknet)17
AS3249 (Telia Eesti)17
AS29247 (OTEnet)17
AS12874 (Fastweb)17
AS56044 (China Mobile)16
AS3209 (Vodafone GmbH)16
AS25106 (Mobile TeleSystems JLLC)16
AS9121 (Turk Telekom)15
AS8412 (T-Mobile Austria)15
AS262374 (FAZZY INTERNET)15
AS14593 (SpaceX / Starlink)6

Figure 2: ASNs exposing S7 devices on port 102.

60 ASNs carry 15 or more exposed services, 6,003 of the 7,435 total. Asahi Net (AS4685) carries 1,084, 86% of Japan’s total. Vodafone Romania (AS12302) carries 560, 95% of Romania’s 591. Turkcell, Vodafone Türkiye and TT Mobil together carry 997 of Türkiye’s 1,025. Verizon Business (236) and T-Mobile USA (55) carry 291 of the 362 in the United States. Six sit on SpaceX Starlink (AS14593). One device in Germany is reachable through a hostname on AVM’s Fritz!Box residential dynamic-DNS domain.

1.3% Sit on Cloud and Hosting Networks

99 of the 7,435 services sit on cloud and hosting providers rather than on carrier or industrial networks.

AS14061 (DigitalOcean)17
AS136258 (BrainStorm Network)14
AS20473 (The Constant Company (Vultr))10
AS63949 (Akamai Connected Cloud)9
AS63473 (HostHatch)9
AS24940 (Hetzner Online)9
AS55933 (Cloudie Limited)4
AS16276 (OVH)4
AS16509 (Amazon AWS)4
AS202053 (UpCloud)4
AS136907 (Huawei Cloud)4
AS9009 (M247)3
AS8075 (Microsoft Azure)2
AS45102 (Alibaba Cloud)2
AS51167 (Contabo)2
AS202422 (G-Core Labs)2

Figure 3: All 16 cloud and hosting autonomous systems carrying an exposed S7 service.

Production industrial control equipment is not normally hosted on a VPS, and several characteristics of this group are consistent with honeypots. We did not confirm the ownership, operator or purpose of any of them. Some may be research or threat-intelligence infrastructure, some vendor test systems, some real equipment reached through a cloud-hosted gateway. Treat them as potential honeypots, not an established category.

Three patterns stand out. One DigitalOcean instance returns a complete S7-300 identity including a plant identifier naming an electrical substation:

plant_id:   [redacted]
module:     Siemens SIMATIC S7-315-2
module_id:  6ES7 315-2EH14-0AB0
serial:     S C-[redacted]
copyright:  SIMATIC S7-300 V3.3

Figure 4: Example of Banner from a hosted S7 service.

Second, instances on AWS, Azure and Vultr in three different regions return the same system name, plant identifier and serial number as each other. The system name is a fictional location and the serial is not a plausible Siemens serial. Third, AS136258 (BrainStorm Network) carries 14 services across ten or more countries returning byte-identical banners, matching on hash, all presenting the same S7-300 model and serial number.

Setting the 99 aside leaves roughly 7,336 services on carrier and enterprise infrastructure.

Which Controllers Are Exposed

5,449S7-1200
399S7-300
265S7-1500
12S7-400

Figure 5: Identified modules by product series, from the 6,268 services returning a full banner.

The S7-1200 is Siemens’ current compact line and the series AA26-231A names. It accounts for about 5,449 identified modules.

ModelPart numberDevices
S7-1215C AC/DC/RLY6ES7 215-1AG40-0XB01,521
S7-1214C AC/DC/RLY6ES7 214-1AG40-0XB01,490
S7-1214C DC/DC/DC6ES7 214-1HG40-0XB0623
S7-1214C AC/DC/RLY (B)6ES7 214-1BG40-0XB0482
S7-1212C AC/DC/RLY6ES7 212-1AE40-0XB0255
S7-1215C DC/DC/DC6ES7 215-1HG40-0XB0234
S7-1212C DC/DC/DC6ES7 212-1HE40-0XB0218
S7-1211C AC/DC/RLY6ES7 211-1AE40-0XB0141
S7-1212C AC/DC/RLY (B)6ES7 212-1BE40-0XB0123
S7-1215C AC/DC/RLY (B)6ES7 215-1BG40-0XB052
S7-1211C DC/DC/DC6ES7 211-1HE40-0XB034
S7-1217C DC/DC/DC6ES7 217-1AG40-0XB017
S7-1211C AC/DC/RLY (B)6ES7 211-1BE40-0XB011
Older V3.x variantsvarious -31 / -30 / -AE30~155

Figure 6: S7-1200 models. The top two, the S7-1215C and S7-1214C AC/DC/RLY, account for 3,011 devices.

SeriesModelPart numberDevices
S7-1500CPU 1510SP (ET 200SP)6ES7 510-1DJ01-0AB040
S7-1500CPU 1512C6ES7 512-1DK01-0AB038
S7-1500CPU 1510SP V36ES7 510-1DK03-0AB019
S7-1500CPU 15126ES7 512-1DM03-0AB017
S7-1500CPU 1511-1 PN6ES7 511-1AK02-0AB015
S7-1500CPU 1513-1 PN6ES7 513-1AL02-0AB013
S7-1500CPU 1515-2 PN6ES7 515-2AM02-0AB012
S7-1500CPU 1511-1 PN6ES7 511-1AK01-0AB011
S7-1500CPU 1515-2 PN6ES7 515-2AM01-0AB010
S7-1500CPU 1515F-2 PN (fail-safe)6ES7 515-2FN03-0AB02
S7-1500Others (516-3xx, 517-3xx, 518-3xx)various~89
S7-300CPU 315-2 PN/DP6ES7 315-2EH14-0AB0162
S7-300CPU 315-2 PN/DP6ES7 315-2AH14-0AB071
S7-300CPU 314C-2 PN/DP6ES7 314-6EH04-0AB023
S7-300CPU 315-2 PN/DP6ES7 315-2AG10-0AB019
S7-300CPU 314-16ES7 314-1AG14-0AB014
S7-300CPU 313C-2 PN/DP6ES7 313-5BG04-0AB010
S7-300CPU 313C PN/DP6ES7 313-5BF03-0AB010
S7-300CPU 317-26ES7 317-2EK14-0AB05
S7-300CPU 317F-2 PN/DP (fail-safe)6ES7 317-2FK14-0AB04
S7-300CPU 315-26ES7 315-2EH13-0AB04
S7-300CPU 312 / 313 / 314 / 318 variantsvarious~77
S7-400CPU 412-5H6ES7 412-5HK06-0AB03
S7-400CPU 412-26ES7 412-2EK07-0AB03
S7-400CPU 412-26ES7 412-2EK06-0AB02
S7-400CPU 414-36ES7 414-3EM06-0AB02
S7-400CPU 414-4H6ES7 414-3XM05-0AB01
S7-400CPU 414-26ES7 414-2XK05-0AB01

Figure 7: S7-1500, S7-300 and S7-400 models.

Siemens announced the S7-300 phase-out in 2023 and states that the S7-300 and ET 200M families remain available until 2033, so the 399 S7-300 modules here are a supported product. What the generation lacks is the access-protection and communication-security design of the S7-1500 line.

The Safety Controllers

Six of the exposed devices carry an F designation across two models: two CPU 1515F-2 PN and four CPU 317F-2 PN/DP. Both were identified from the module name and order number returned in the device’s own banner, where the F appears in the CPU name and in the order number’s function group: 6ES7 515-2FN03-0AB0 and 6ES7 317-2FK14-0AB0. F-CPU is Siemens’ own term for these devices (SIMATIC Safety - Configuring and Programming), and it denotes a specific engineering category rather than a marketing label.

In Siemens’ own terms, safety functions in a SIMATIC Safety system exist “to bring the system to a safe state or maintain it in a safe state in case of a dangerous event”, and they run in the safety-related program on the F-CPU together with fail-safe I/O that process signals from devices such as emergency-stop pushbuttons and light barriers (SIMATIC Safety - Configuring and Programming). The S7-300 and S7-400 equivalents are documented separately in S7 F/FH Systems - Configuring and Programming.

These systems are certified against functional-safety standards: SIMATIC Safety F-systems can meet Safety Integrity Level 3 under IEC 61508 and Performance Level e, category 4, under ISO 13849-1. Siemens documents the wider product family under Safety Integrated. Communication between an F-CPU and its fail-safe I/O uses the PROFIsafe profile.

The practical meaning is that an F-CPU is the device that stops a process to prevent injury or plant damage. The 1515F observed in Mexico returns its full serial number, hardware revision, production date and module name. An internet-reachable F-CPU should be treated as an incident, not a finding.

Firmware

FirmwareDevicesDetail
4.5.x2,0724.5.1: 1,686 · 4.5.0: 299 · 4.5.3: 53 · 4.5.2: 34
4.6.x6444.6.0: 610 · 4.6.1: 34
4.7.x1744.7.0: 130 · 4.7.3: 44
4.4.x4714.4.1: 351 · 4.4.0: 120
4.3.x~3404.3.1: 336+
4.2.x~1,2004.2.1: 393 · 4.2.0: 306 · 4.2.2: 282 · 4.2.3: 219
4.0.x–4.1.x~3324.1.3: 248 · 4.1.1: 50 · 4.0.0: 34
3.x~450S7-300 range
2.x~110S7-300 range
Not reported1,132N/A

Figure 8: Firmware distribution across the 6,268 services reporting a version.

About 46% of reporting devices run 4.5.x or newer. Around 24% run 4.0.x–4.2.x, and a further 9% run 3.x or 2.x. The single most common version in the dataset is 4.5.1, on 1,686 devices.

Two caveats. The 4.x versions are the S7-1200 firmware line while the 3.x and 2.x figures come from S7-300 controllers, which version separately, so the buckets are ordered by age rather than by one release history. And the current S7-1200 release is V4.7.3, on 44 devices. Patching closes known vulnerabilities but does not close the exposure, which is reachability rather than a defect. The firmware spread matters because a version string is what turns generic interest into a targeted exploit.

What To Do About It

Block port 102 at the perimeter. The advisory’s first recommendation, and the only measure that addresses the condition. Remote engineering access belongs behind a VPN or jump host.

Audit cellular and satellite uplinks specifically. Mobile operators carry a large share of this dataset, and those links are commissioned outside IT and absent from inventories.

Push remediation to the carrier layer. Asahi Net, Vodafone Romania and the three Turkish mobile operators account for 2,641 services, 36% of the total. Remediation there removes more exposure than any customer-by-customer effort.

Enable CPU access-level protection. The S7-1200 and S7-1500 families support password-protected access levels restricting read and write over S7comm.

Treat exposed F-CPUs as incidents. Six fail-safe controllers are reachable. Verify every F-series device independently of the general inventory.

Patch, but do not mistake it for a fix. A third of reporting devices are below 4.3. Closing that removes known vulnerabilities; it does not make an exposed PLC safe.

Watch for snap7 where it does not belong. Unexplained python-snap7 or snap7.dll on an engineering workstation, or outbound port 102 from a host with no reason to speak S7comm, is worth investigating.

Attribute cloud-hosted results with care. Confirm what a host is before it enters a threat feed or a victim count.

Conclusion

AA26-231A says the capability to manipulate S7 controllers is being built now. The data says the targets are in place: 7,435 services across 77 countries, all on port 102, a third of reporting devices below firmware 4.3, and six fail-safe controllers among them.

The concentration is the encouraging half. Five carriers account for 2,641 of the 7,435 services, 36% of the total, which means a small number of parties could remove a large share of this surface.

All figures reflect Modat Magnify observations from 20 August 2026, across the complete 7,435-record dataset. Plant identifiers, serial numbers, hostnames and addresses are redacted throughout. Every observation is passive: no credentials were tested, no authentication was bypassed, and no PLC memory was read or written.

Sources

Intent leaves a trace.

Talk to us about your needs