The US National Security Agency said on 19 August that attackers were gathering information about US-based Siemens controllers and developing tools to exploit them. It reported the use of AI-generated attack scripts disguised as legitimate monitoring tools. [2]
The agency warned that successful attacks on poorly protected controllers could disrupt industrial processes or damage equipment. Neither its announcement nor Siemens' bulletin identifies attacks on yachts or ships. [1] [2]
Siemens' recommendations
Siemens recommends keeping devices and systems on current software and firmware to reduce exposure to known vulnerabilities. It also advises removing devices from inadequately secured networks or adding protection such as firewalls. The warning covers insecure internal networks as well as internet exposure. [1]
Customers are advised to replace default passwords with strong, unique credentials and follow the security instructions for their specific equipment. The bulletin does not announce a new vulnerability or provide a single firmware fix for the reported threat. [1]
Relevance to vessels using S7 controllers
For vessels fitted with S7 equipment, the controller model and installed firmware are the starting information for checking applicable product guidance. NIST's operational technology security guide recommends recording hardware details and software versions in the asset inventory. [3]
IMO's maritime cyber guidelines already call for an inventory of onboard digital systems and their network connections. They recommend separating machinery-control networks from general IT networks and protecting them from internet-facing systems. Maintenance computers and third-party connections are also covered by the guidance. [4]
Updates to operational equipment require compatibility checks. NIST recommends that both the vendor and operator test software updates before deployment, with any necessary downtime planned in advance. Its guidance notes that changes may also require the control system to be revalidated. [3]
References
[1] SSB-104599: Increasing Cyber Threats to Industrial Control Systems. Siemens ProductCERT, V1.3, updated 21 August 2026. Manufacturer security bulletin.
[2] NSA and Others Release Report on Active Threats of Programmable Logic Controllers. National Security Agency, 19 August 2026. Official advisory announcement.
[3] Guide to Operational Technology (OT) Security — NIST SP 800-82 Rev. 3. NIST, September 2023. Guidance on asset inventories and safe management of OT updates.
[4] Guidelines on Maritime Cyber Risk Management — MSC-FAL.1/Circ.3/Rev.3. IMO, 4 April 2025. Maritime guidance on digital-system inventories and network protection.