Defending Against an Active Threat to Siemens S7 Series PLCs
Critical infrastructure incidents no longer unfold only across physical assets and cyber systems. They also unfold in an infospace shaped by digital platforms whose algorithms favour speed, emotional intensity, and visibility over verification. For operators, this means that rumour, distortion, and misleading narratives can become part of the incident environment before the first official statement is issued. That is no longer just a communications issue. It is a resilience issue.
The problem is not limited to deliberate disinformation campaigns by hostile actors. A significant part of the risk arises from the normal operation of large social media platforms. During an outage, transport failure, communications disruption, or industrial accident, there is almost always an early information vacuum. Official facts are incomplete, technical assessments are still underway, and restoration timelines remain uncertain. Into that gap flows the content platforms are most likely to amplify. In practice, that often means the most dramatic, emotionally charged, or speculative interpretation of events.
The consequences are operational, not merely reputational.
First, algorithmically amplified misinformation can distort public behaviour. False or exaggerated claims about the scale of an incident, the existence of secondary hazards, or the reliability of official updates can influence how people respond in real time. In an infrastructure emergency, resilience depends partly on public cooperation: passengers need clear guidance, consumers may need to reduce demand, and affected communities need to know which channels to trust. Confusion in the information environment weakens that cooperation.
Second, it can place additional strain on response systems. When misleading narratives spread quickly, emergency services, customer contact centres, and public authorities may face surges of enquiries, complaints, or panic-driven reactions that do not correspond to the technical reality of the event. This diverts attention and capacity at precisely the moment when disciplined prioritisation matters most.
Third, it can damage trust in ways that outlast the incident itself. Even where restoration is technically successful, the dominant online narrative may frame the event as evidence of incompetence, secrecy, or negligence. Once that framing becomes established, later incidents become harder to manage because the baseline level of trust has already been weakened.
For this reason, critical infrastructure operators should stop treating the infospace as a downstream issue to be handled only after the technical response is underway. In the platform age, the narrative environment develops in parallel with the operational incident, and often faster than formal communication processes can respond. The information dimension therefore needs to be built into resilience planning in advance.
Three practical steps would make a real difference.
The first is to treat narrative monitoring as part of situational awareness during significant incidents. Operators already monitor technical status, cyber indicators, and service impacts. They should also have a structured way to assess what claims are circulating online, which narratives are gaining traction, and whether those narratives are affecting behaviour. While this is established practice in advanced crisis communication teams, it remains rare in CIP incident management structures — and that gap needs to close.
The second is to invest in trusted communication channels and pre-prepared messaging frameworks before a crisis occurs. Credibility cannot be improvised in the middle of a major outage. Organisations that have already established visible, consistent, and recognisable public channels — whether through direct social media presence, relationships with local authorities, or pre-agreed communication protocols with emergency services — are in a much stronger position to reach the public quickly with accurate information when it matters. Equally important is preparing draft holding lines and narrative frameworks for the most foreseeable incident types: a grid outage, a transport disruption, a communications failure. When the information vacuum opens, the difference between responding in minutes and responding in hours is often the difference between shaping the narrative and chasing it.
The third is to update crisis training and exercises. Tabletop exercises should not simulate only the technical disruption. They should also simulate the platform dynamics surrounding it: rumour cascades, miscaptioned images, false attributions of cause, and competing unofficial narratives. That is now part of the real operating environment, and preparedness should reflect it.
Critical infrastructure protection has always required attention to the wider conditions that shape disruption. Today, one of those conditions is the infospace. Algorithmic amplification is not an abstract media issue or a secondary public relations concern. It is part of the environment in which incidents are interpreted, escalated, and managed. Resilience planning should reflect that reality.
Antonio Scala is a physicist and Research Director at CNR-ISC. His research focuses on complex networks, information dynamics, and critical infrastructure resilience.
Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026.
With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly.
However, cybercrime legislation is fragmented and AI readiness in law enforcement agencies remains alarmingly low.
The 40-page report draws on survey data from 36 African member countries and highlights a defining shift: cyber-criminality has evolved from isolated incidents into an industrialized, borderless ecosystem.
East Africa emerged as a hub of mobile money fraud and infrastructure-targeted ransomware.
Business email compromise and romance scams targeting both corporate and individual victims were prolific in Central and West Africa.
Southern Africa’s ultra-high connectivity makes it a magnet for global threat actors seeking maximum disruption.
The financial toll of cybercrime in Africa is significant.
Since 2024, cybercrime-related losses have more than doubled, from USD 192 million to USD 484 million, driven primarily by AI-facilitated scams, credential harvesting, and automated social engineering campaigns.
According to the report, in 2025, online scams continued to be the most reported type of cybercrime, with attackers leveraging mobile money platforms, social media and AI to reach their targets.
Notably, 72 per cent of surveyed countries reported the presence of scam centres, with the highest concentration in Southern and West Africa.
AI-enabled cyberthreats
Digital sextortion and online harassment, often facilitated by AI-generated deepfakes and synthetic media, remained pervasive, with some 600,000 sextortion detections recorded by TrendAI, one of several partners working with INTERPOL.
Similarly, the sophistication of Business E-Mail Compromise (BEC) schemes increased dramatically, with AI used to generate highly convincing e-mail correspondence, with Africa-based threat actors targeting victims in Europe and North America using infrastructure located across multiple jurisdictions.
The report reveals that the absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud.
This vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities.
Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names.
Neal Jetton, Director of INTERPOL’s Cybercrime unit said, “Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion.
“However, we see that when countries work together, cybercriminal infrastructure can be identified, disrupted and dismantled.”
Meaningful transnational progress is visible. In 2025, 17 countries enacted or amended cybercrime legislation, including the launch of an online reporting platform in Senegal aimed at enhancing the response to online violations affecting children.
At the same time, regionally coordinated capacity building initiatives continue to strengthen long-term cyber resilience.
Operational cooperation is also delivering noteworthy results.
Four high impact cybercrime operations coordinated by INTERPOL including Operation Serengeti 2.0, Operation Contender 3.0, Operation Sentinel and Operation Red Card 2.0 collectively led to more than 1,500 arrests, the seizure of hundreds of devices and the recovery of over USD 100 million.
In its recommendations, the report calls for standardized digital forensic capabilities, enhanced cross-border cooperation, investment in AI literacy among law enforcement officers and formal-public private partnership to support effective prevention, detection and response.
CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.
These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.
CISA recommends organizations implement the following mitigations:
- Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
- Enable password protection and change default passwords.
- Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.
After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password. Note: Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation’s IMPORTANT NOTICE: Restoring Access to a MicroLogix™ 1400 Controller When the Password Is Unknown for guidance addressing this activity.
To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance:
- CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology
- United Kingdom's National Cyber Security Center: Secure Connectivity Principles for Operational Technology
- Federal Bureau of Investigation (FBI): Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions
For additional support, contact the Environmental Protection Agency’s Cybersecurity Technical Assistance Program for the Water Sector.
The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) released an updated joint Cybersecurity Advisory Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.
This update re-emphasizes the ongoing threat from Iranian-affiliated advanced persistent threat (APT) actors targeting internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other brands/manufacturers. These attacks have resulted in operational disruptions and financial losses across multiple U.S. critical infrastructure sectors, including Government Services and Facilities, Water and Wastewater Systems, and Energy.
What’s New in This Update:
• Expanded Targeting: The advisory now includes observed targeting of Schneider Electric and Siemens PLCs, in addition to Rockwell Automation/Allen-Bradley and potentially other branded/manufacturer devices.
• Updated Technical Details: New information on threat actor tactics, including use of configuration software to exfiltrate device project files, and expanded details on targeted ports and device models.
• Enhanced Mitigations: Additional recommendations for securing cellular modems, implementing isolated architectures, validating project files, and detecting malicious changes in reusable code modules (such as Add-On Instructions/AOIs).
• New Indicators of Compromise (IOCs): Updated tables of internet protocol (IP) addresses and timeframes associated with Iranian-affiliated APT activity.
Iranian-affiliated APT actors continue to adapt their tactics, targeting a wider range of devices and sectors. Proactive review of this advisory and implementation of the recommended mitigations are critical to defending your organization’s OT assets and ensuring operational resilience.