Six federal agencies looked at the same water utility campaign this newsletter has tracked since July and concluded the next phase is already underway: attackers using AI to write custom exploitation scripts against the exact PLCs those utilities run, disguised as ordinary monitoring software. Separately, a ransomware crew that has spent years mastering mass exploitation of enterprise file-transfer and PLM software added nearly 50 companies to its leak site in a single week, among them a financial technology firm processing infrastructure for hundreds of banks and credit unions. A South Carolina hospital system is still fighting off extortion posts on its own hijacked Facebook page three weeks after its initial breach, and a Manitoba hospital is a week into recovering from ransomware that reached its door locks and HVAC controls before it reached anything resembling a server room.
This week: what it means when CISA calls out an AI-assisted attack campaign against critical infrastructure for the first time, why a single PLM vulnerability turned into a nearly 50-victim extortion wave spanning finance, healthcare, and energy, and why two hospitals a continent apart are learning the same lesson about physical systems on IT networks.
Federal Agencies Warn of AI-Generated Exploit Scripts Targeting Siemens PLCs Across US Water, Energy, and Manufacturing Sectors
What happened:
On August 19, the NSA, CISA, FBI, EPA, and DOE issued a joint advisory warning of an active threat against internet-exposed Siemens S7 Series programmable logic controllers, the industrial computers that run pumps, valves, and other physical processes across water and wastewater, energy, critical manufacturing, chemical, food and agriculture, and commercial facilities sectors, with Siemens S7 units also present in the defense industrial base. The agencies said threat actors are conducting reconnaissance and exploit development now, not simply theorizing about future attacks, and explicitly tied the activity to the broader wave of attacks against US water and wastewater systems this column has followed since late July.
Technical details that matter:
Attackers are using internet scanning services, including Censys and ZoomEye, to identify exposed S7 PLCs running outdated firmware or weak authentication. The advisory states the actors are using AI to generate Python exploitation scripts built on the snap7.dll and python-snap7 libraries, which communicate with S7 devices over the S7comm protocol, and are disguising these tools as legitimate OT monitoring software. Successfully deployed, the scripts can read and write PLC memory, configuration data, and ladder logic programs, meaning an attacker could alter how the physical equipment actually behaves rather than simply viewing data about it. No named victim or confirmed disruptive incident has been publicly tied to this specific activity yet; the agencies describe it as reconnaissance and capability development, the stage that precedes an attempt at disruption.
Why critical institutions should care:
This is the first time US agencies have formally called out an AI-assisted campaign against operational technology by name, and the timing is not coincidental: it follows directly from the Iran-linked water utility attacks across 12 or more states that this newsletter has covered since late July, and from last week’s disclosure that AI-assisted development played a role in a separate Chinese-language operation against government targets. AI lowers the expertise bar for building a working exploit against a specific PLC model, which changes the threat model for smaller utilities and manufacturers that have historically relied on obscurity, few attackers bothered writing custom tooling for a small water district’s specific hardware. Any institution running Siemens S7 PLCs, or any internet-exposed PLC of any brand, should treat this advisory as the operative fact regardless of whether their specific model is named: remove unnecessary internet exposure, patch and update firmware, and treat ongoing reconnaissance against exposed OT devices as a leading indicator, not background noise.
Key sources:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
- https://therecord.media/nsa-fbi-warns-of-hackers-using-ai-generated-tools-critical-infrastructure
- https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/
- https://www.cybersecuritydive.com/news/ai-hackers-siemens-s7-devices-cisa-fbi/828321/
Cl0p’s PTC Windchill Campaign Names Nearly 50 Victims, Including a Financial Technology Firm Serving Hundreds of Banks
What happened:
Cl0p, the Russia-linked extortion group behind the 2023 MOVEit and GoAnywhere mass-exploitation campaigns, began publicly naming victims on August 12 in a new campaign built around CVE-2026-12569, a critical (CVSS 9.8) unauthenticated remote code execution flaw in PTC’s Windchill PDMLink and FlexPLM product lifecycle management platforms. By August 14, reporting put the claimed victim count near 50 organizations, including Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, and Mindray. GE was initially listed and later removed. Fiserv, a financial technology company whose platforms support core banking and payment processing for hundreds of banks and credit unions, said its review to date found no evidence that customer, banking, transaction, or personal data was compromised. Philips confirmed a contained attempted compromise of a specific enterprise server; Shell and GE said they were investigating.
Technical details that matter:
PTC disclosed CVE-2026-12569 on June 17, and CISA added it to the KEV catalog on June 25, but Ransom-ISAC assesses limited zero-day exploitation likely began in early June, before any patch existed. ReliaQuest confirmed mass exploitation by Cl0p affiliates in late July, chaining a FlexPLM WSDL information leak with the Windchill deserialization flaw to achieve unauthenticated remote code execution and drop JSP web shells. ReliaQuest describes the web shell as a fully equipped extortion platform in its own right: it maps sensitive vault data, decrypts every credential stored in the Windchill keystore, and includes a custom Java class loader that lets the operators execute arbitrary additional code inside the application process, effectively an unlimited backdoor for lateral movement, ransomware deployment, or persistence. Cl0p also ran a parallel pressure campaign, sending emails with the subject line referencing a Windchill data leak from previously compromised internal accounts to hundreds of employees at each target organization simultaneously. More than 30,000 organizations worldwide run Windchill or FlexPLM. Consistent with its MOVEit and GoAnywhere playbook, Cl0p appears to be running exfiltration-only extortion rather than encryption.
Why critical institutions should care:
This is a supply chain story wearing an industrial-espionage costume. PLM software sits deep inside engineering and product-development workflows, which is why the claimed victim list skews toward manufacturing and energy, but the presence of a major financial services technology vendor on that list is the detail that should worry institutional leaders most: Fiserv’s own review found no customer or banking data exposure, but that determination came from Fiserv’s internal investigation, not from an independent audit, and the incident illustrates how a vulnerability in an engineering tool having nothing to do with financial services can still put a financial infrastructure provider on a ransomware leak site. Any critical institution that depends on a vendor for reasons unrelated to that vendor’s core financial or clinical function, an insurer’s PLM system, a hospital’s parts-tracking software, should ask whether their vendor risk assessments account for exposure through tools the vendor uses for entirely different purposes than the service the institution buys from them.
Key sources:
- https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/
- https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign/
- https://thearabianpost.com/cl0p-widens-data-theft-campaign-across-global-firms/
- https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/
Update: AnMed Health Still Fighting Extortion Pressure Three Weeks After Initial Breach
What happened:
AnMed, a nonprofit health system with four hospitals across South Carolina and Georgia, disclosed a ransomware attack on July 26 that took its network offline and forced closures across nearly 80 facilities. On August 10 and 11, a group calling itself The Gentlemen took over AnMed’s Facebook page with dozens of posts claiming to have exfiltrated 6 terabytes of data, including records tied to HIV-positive patients, suicide registries, sexual assault and rape victims, mental health treatment, abortion care, genetic data, patient Social Security numbers and dates of birth, and autopsy and police evidence. Facebook removed the page shortly after. AnMed has not confirmed the attackers’ identity or verified any of the data-theft claims. As of this week, patients with an active MyChart account and a mobile number on file have begun regaining access to their health records through a text-verification process, an incremental sign of recovery three weeks into the incident.
Technical details that matter:
AnMed itself has disclosed almost no technical detail: no confirmed attack vector, no confirmed ransomware family, no confirmed initial access method. What is documented comes from research into The Gentlemen as a group: active since around July 2025, operating a C and Go-based cross-platform encryptor, offering affiliates a 90 percent revenue share (among the highest in the ransomware-as-a-service market), and deploying a centralized EDR-killer toolset researchers have named GentleKiller alongside worm-like lateral movement capable of compromising Active Directory and connected OT environments within hours of initial access. At least one cybersecurity source has cautioned that the AnMed attackers’ use of The Gentlemen’s name and imagery could itself be unverified, meaning the true identity of whoever is applying pressure against AnMed remains an open question even as the pressure campaign continues.
Why critical institutions should care:
The data categories the extortion posts named, if genuine, are among the most sensitive and consequential a healthcare provider holds; sexual assault, abortion, and mental health records carry legal, safety, and reputational stakes well beyond a typical medical record. But the more durable lesson for institutional leaders is the extortion mechanism itself: a compromised or spoofed social media account became the pressure channel, not a dark web leak site, which means public-facing communications teams need incident response training as much as IT does. Three weeks in, patients still lack full record access, and the health system still cannot confirm what was actually taken, illustrating how long recovery from a ransomware incident against clinical infrastructure runs even when patient safety itself is not directly threatened.
Key sources:
- https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response
- https://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/
- https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/anmed-hit-with-data-theft-claim-after-facebook-hack/
- https://wgog.com/new-message-from-anmed-health/
Update: A Week Into Recovery, Winnipeg Hospital’s Ransomware Incident Shows What Happens When IT and Building Systems Share a Network
What happened:
Shared Health, which operates Winnipeg’s Health Sciences Centre, Manitoba’s largest hospital, and Cancer Care Manitoba, discovered a ransomware incident on August 10 affecting facility maintenance systems rather than clinical or patient-record systems. Door access controls, elevators, and centralized HVAC monitoring were all disrupted. In an August 17 update, a week after discovery, Shared Health confirmed recovery work was still ongoing and reiterated that patient care and clinical operations had not been affected throughout. No group has publicly claimed responsibility, and Shared Health has not disclosed how the attackers gained initial access.
Technical details that matter:
The disclosed impact is narrower than most incidents this newsletter covers, but notable for what it reveals about network architecture rather than for a sophisticated intrusion chain: ransomware reached building management systems, door locks, elevators, and HVAC controls, none of which have an obvious reason to share a network segment with whatever system the initial infection landed on. Central HVAC monitoring was disrupted, but the physical equipment itself kept running and was switched to local monitoring, meaning the safety-critical function survived even though the monitoring layer did not. That distinction, between a control system continuing to operate safely in a degraded state and a monitoring layer going dark, is doing a lot of work in Shared Health’s public statements, and it is the reason patient care could continue uninterrupted despite the disruption to physical infrastructure.
Why critical institutions should care:
This is the second facility-management ransomware incident at a major hospital this newsletter has covered in recent months, and the pattern is the same one CERT Polska documented in the private-APN pivot into Poland’s energy sector two weeks ago: systems assumed to be separate from clinical or corporate IT turn out to share enough network access that ransomware reaches them anyway. A week-long recovery timeline for door locks and elevators at a 780-bed trauma center is itself a safety and operations concern independent of any data theft, and the fact that no attacker has claimed credit or demanded payment publicly suggests this may be collateral damage from a broader untargeted campaign rather than a deliberate attack on hospital infrastructure specifically, though that is inference rather than confirmed fact. Any critical institution running building management systems, HVAC controllers, door access, physical security, on the same network as IT infrastructure should treat this as a prompt to verify actual segmentation rather than assumed segmentation.
Key sources:
- https://www.cbc.ca/news/canada/manitoba/winnipeg-hsc-ransomware-cyberattack-9.7310005
- https://www.govinfosecurity.com/ransomware-attack-disables-canadian-hospitals-doors-hvac-a-32535
- https://www.cbc.ca/news/canada/manitoba/health-sciences-centre-ransomware-hack-9.7302058
- https://asimily.com/blog/how-segmentation-contains-a-hospital-ot-ransomware-attack/
The Pattern This Week
Every story this week involves a system reaching further than the institution expected it to. AI-generated exploit scripts extend attacker capability into infrastructure that used to be protected mainly by attackers not bothering to learn its specific protocols. A vulnerability in an engineering lifecycle-management platform reached into a financial technology vendor that has nothing to do with product design. And at two hospitals a continent apart, whatever compromised the network first reached all the way into door locks, elevators, and HVAC controls that had no operational reason to be reachable from wherever the ransomware started.
The throughline connects to what this column has been tracking since the water utility campaign began in late July: the industries under pressure are the ones where physical consequences ride on IT decisions made for reasons that had nothing to do with physical safety. AI narrows the skill gap standing between reconnaissance and a working exploit. Vendor risk keeps hiding in tools that serve a completely different function than the one an institution actually contracted for. And segmentation, or the lack of it, keeps being the variable that decides whether a ransomware incident stays contained to data or reaches into the physical world.
See you next week.
What Your Business Can Do This Week
- If your organization operates any internet-exposed programmable logic controller, Siemens or otherwise, treat the CISA/NSA/FBI advisory as applicable to you regardless of brand. Confirm firmware is current, remove unnecessary internet exposure, and strengthen authentication. Reconnaissance against your specific PLCs should be treated as a leading indicator of intent, not routine internet noise.
- If you use PTC Windchill or FlexPLM anywhere in your organization, including through a vendor or contractor, confirm the patch for CVE-2026-12569 has been applied and audit for JSP web shells and unusual Java class loader activity. Given Ransom-ISAC’s assessment that exploitation began before the public patch, treat any instance that was internet-reachable since early June as a potential credential-rotation event, and rotate all secrets stored in the Windchill keystore.
- Extend vendor risk assessments to cover tools your vendors use for purposes unrelated to the service they provide you. Fiserv’s appearance on Cl0p’s leak site came through an engineering PLM platform, not a financial system. Ask key vendors what non-core software touches your data indirectly, not just what directly processes it.
- If your facility runs building management systems, door access, HVAC, elevators, on any network segment reachable from general IT infrastructure, verify actual network segmentation rather than assumed segmentation. Two hospital ransomware incidents in recent weeks reached physical building systems that had no clear operational reason to be reachable from wherever the initial infection landed. Confirm your own architecture doesn’t have the same gap.

