Forescout Study Demonstrates AI-Assisted Attacks on Industrial Hardware, But High Costs Limit Near-Term Risk
Researchers successfully used generative AI tools to port exploits across industrial controllers, though technical barriers and high API costs make widespread threat adoption unlikely for now.

Artificial intelligence models are reaching a technical threshold where they can assist in compromising industrial hardware, though high financial expenses and operational complexity currently prevent widespread adoption by standard cybercriminals, according to new research from cybersecurity firm Forescout first reported by TechRadar Pro.
The experiment evaluated whether modern AI technologies could automate the process of discovering and executing zero-day security vulnerabilities within Operational Technology (OT) environments. Researchers specifically focused on Programmable Logic Controllers (PLCs), which supervise physical machinery across industrial and utility operations and traditionally operate on proprietary, closed-source software.
During the test, Forescout succeeded in porting a remote code execution (RCE) flaw from one PLC device to a different model. The operation initially caused a Denial of Service (DoS) condition that crashed the target unit before establishing a functional remote code execution capable of running custom ARM shellcode supplied by the researchers.
Despite demonstrating a functional proof of concept, the study underscored major technical and practical limitations. Developing the final remote code execution required continuous intervention from expert human researchers, and the API calls used during that phase alone cost more than $500.
Attempts to expand the exploit's reach past the initial code execution phase resulted in permanently rendering the physical PLC inoperable. Forescout researchers highlighted in their report that while AI-supported exploitation of industrial systems is technically achievable, the steep financial burden, technical difficulty, and specialized knowledge required currently make these techniques less appealing to cybercriminals than traditional, less expensive attack methods.
However, the research points to potential long-term risks regarding well-funded threat groups and nation-state adversaries. For state-backed actors seeking to disrupt critical utilities, spending hundreds of dollars on API usage represents a minor cost—a reality illustrated by high-profile industrial incidents such as the 2025 attack by the Sandworm group against power providers in Poland.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



