Home / Technology / AI Cracks PLC Security: Is Your Factory Next?
AI Cracks PLC Security: Is Your Factory Next?
3 Sep
Summary
- AI successfully ported RCE exploits to Programmable Logic Controllers.
- Exploitation required significant researcher input and over $500 in API costs.
- Nation-state actors are a concern, as shown in a past attack on Poland.

Researchers have demonstrated that Artificial Intelligence (AI) can be used to port Remote Code Execution (RCE) exploits to Programmable Logic Controllers (PLCs), achieving both Denial of Service and shellcode execution. This proof-of-concept, while successful, demanded significant researcher input and incurred costs exceeding $500 in API usage, rendering it impractical for common cybercriminals at present.
Despite these limitations, the potential for AI-driven attacks on Operational Technology (OT) is a serious concern, particularly for well-resourced nation-state actors. This threat landscape mirrors past incidents, such as the 2025 Sandworm attack targeting Poland's electricity suppliers, highlighting the ongoing risks to critical infrastructure.