The American Hospital Association is warning hospitals of an active cyber threat targeting building-control systems, after the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI and two other federal agencies issued a joint advisory about Siemens S7 Series programmable logic controllers.
The devices run critical hospital systems such as climate control and access control. Threat actors are using artificial intelligence to generate exploitation scripts disguised as legitimate monitoring tools, then scanning the internet to find PLCs running outdated or poorly protected software, according to the advisory.
The agencies said the activity likely represents reconnaissance and capability development rather than completed attacks, aimed at preparing for future operational effects against critical infrastructure. The Department of Energy and the Environmental Protection Agency also signed the notice, which urges all PLC owners and operators to inventory their Siemens S7 Series controllers, apply security patches immediately, strengthen access controls and monitor for unauthorized activity.
Scott Gee, deputy national advisor for cybersecurity and risk at the AHA, said in an Aug. 20 news release that the warning “applies more broadly” than Siemens devices alone. Mr. Gee said hospitals and health systems should build an accurate inventory of PLCs in their environments and work with their cybersecurity teams to prioritize protecting them. He recommended disconnecting vulnerable PLCs from the internet or placing them on isolated networks.
The Aug. 18 advisory adds to a string of federal warnings this month about active threats to hospital and health system infrastructure, including updated guidance on the Medusa and Gunra ransomware groups.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.