Cyber threat actors use artificial intelligence in an active global campaign to disrupt internet-exposed programmable logic controllers

The Canadian Centre for Cyber Security (Cyber Centre) is warning Canadian organizations of an active global campaign in which cyber threat actors are targeting and attempting to disrupt programmable logic controllers (PLCs) that are exposed to the internet. The Cyber Centre and its partners have previously warned that cyber threat actors are targeting internet-accessible industrial control systems and operational technologies (ICS/OT) to disrupt water facilities and other critical services in Canada and abroad. This cybersecurity advisory describes how threat actors are using artificial intelligence (AI) to find and attack these devices.

The threat to Canadian organizations

The Cyber Centre continues to observe cyber threat actors targeting and attempting to disrupt internet-exposed ICS/OT systems in Canada. In October 2025, the Cyber Centre observed several incidents affecting ICS/OT systems in Canada. In one incident, a threat actor manipulated water pressure valve controls at a municipal water system, causing minor impacts to water service delivery.

In July 2026, the United States' Cybersecurity and Infrastructure Security Agency (CISA) reported a significant increase in attacks against PLCs at water and wastewater utilities. Threat actors changed passwords to lock operators out of their controllers and took devices offline by changing their network addresses. This activity resulted in boil water advisories and sustained manual operations at affected utilities.

Threat actors are testing and refining their exploitation techniques against specific PLC models. They are focusing their activity on specific sectors and facilities. Our partners assess that this activity is likely persistent reconnaissance intended to develop capabilities and prepare to cause operational effects against critical infrastructure. The most targeted sectors include: critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. Threat actors are targeting organizations of every size.

Canada has not experienced a high-impact ICS/OT incident so far. However, we assess that the threat to ICS/OT owners and operators is increasing and that future incidents will likely be more severe.

To monitor and mitigate this threat, we encourage Canadian organizations to consult the guidance linked below on reducing internet exposure, securing remote access, and protecting ICS/OT systems.

The threat to internet-exposed PLCs

PLCs are small industrial computers that control physical processes, such as pumps, valves, pressure, and temperature. They are used in facilities across every critical infrastructure sector. A threat actor with access to a PLC can disrupt industrial processes, damage equipment, endanger worker and public safety. The impacts can spread across interconnected systems. While PLCs are a frequent target because they directly control physical processes, other internet-exposed ICS/OT assets, including human-machine interfaces (HMIs), are also at risk.

Cyber threat actors use internet scanning services to find exposed PLCs and take advantage of weak, default, or absent passwords to access them. After gaining access, threat actors have changed device settings, disabled alarms, and locked operators out of their systems, forcing facilities into manual operations while service is restored.

Many PLCs are exposed to the internet unintentionally and without the knowledge of the organizations that own them. These systems can be readily identified using public internet scanning services. A control system may be isolated from an organization's enterprise information technology (IT) network but still be accessible from the internet. A cellular modem or a vendor remote access connection installed during commissioning or maintenance may provide access. These connections are often undocumented, retained after they are no longer required, and missed by routine attack surface scans. Organizations should verify that their systems cannot be accessed from the internet.

Organizations should also identify and secure all internet-accessible ICS/OT assets, not only PLCs, and ensure remote access is properly controlled and monitored.

The risk from third parties and system integrators

The risk of unknown exposure is greatest for organizations that rely on system integrators or third-party service providers who may have remote access to their PLCs for maintenance, monitoring, or support activities. Even organizations with mature cyber security programs should validate their external connections with their integrators and service providers and scan the internet address ranges they own to identify exposed systems, especially connections set up by third parties that are no longer actively managed or documented.

Unclear division of roles and responsibilities between organizations and their service providers often creates gaps that leave critical systems unprotected. We encourage organizations to work closely with their integrators and service providers to ensure that systems are implemented securely and maintained throughout their lifecycle, and to consider including maintenance, security responsibilities, and liability in service agreements, in alignment with security best practices.

Cyber threat actors use artificial intelligence to attack PLCs

As we noted in our cyber threat bulletin on non-state activity targeting Canadian operational technology, AI tools capable of supporting cyber threat activity are rapidly improving and becoming increasingly available. These tools allow even low-sophistication threat actors to conduct more complex and disruptive attacks against ICS/OT systems. We assess that as these tools become more widely available, opportunistic attacks against internet-exposed systems will likely also become more frequent.

As part of this campaign, threat actors are using AI to generate exploitation scripts that they disguise as legitimate monitoring software, dramatically reducing the expertise and time needed to develop working attack tools. It is very likely that the actors continue to operate despite public reporting outlining their activities. Our partners issued their most recent warnings in August 2026.

Useful resources

Refer to the following resources for more information and useful advice and guidance.

Reports and advisories

Advice and guidance

Date modified: