ICS/OT

Iran-Linked Hackers Shut Down UK Power Plant for Four Days

The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.

Power grid security

Iran-linked hackers reportedly managed to shut down a British power plant for four days in July 2026. The story was broken by the Telegraph newspaper on August 22, 2026. That it took so long to become public knowledge immediately says two things. Firstly, it was not a major power plant since the effect would have been immediately noticed, and secondly, the authorities wished to keep news of the attack as low key as possible.

Other newspapers (for example the BBC, the Guardian and the Financial Times) have since published their own stories, largely based on the Telegraph account. There has been virtually no information coming from the expected official sources, such as the NCSC. The BBC report comments, “While the Western cyber-security world is braced for attacks either from the state [of Iran] or hackers linked to the state as a result of its conflict with the US this year, there has been little activity so far.”

This last point is clearly wrong. Since the outbreak of the war with US / Israel, Iran affiliated cyber groups have attacked multiple targets in the US (water, critical infrastructure and military-linked assets), Israel (military, government, energy, healthcare, and more), GCC targets in UAE, Bahrain, Kuwait, Qatar, Saudi Arabia, and Europe (Cyprus, Romania and now Britain). This does not equate to ‘little activity so far’, so the expansion into the UK should not be downplayed. And, in general, cybersecurity experts are not downplaying it.

“The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption. That raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?”, asks Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.

A related question worth asking is whether Iranian hackers are probing UK defenses for increased aggression – and is this attack repeatable. “The loss of a single facility like this can be well managed and as reported, doesn’t constitute a major risk to stability, but these are often very repeatable attacks that could be deployed at scale,” posts Phil Tonkin, field CTO at Dragos, on LinkedIn.

Rafael Narezzi, CEO of Centrii, has a similar concern. He points out that attackers don’t worry about the size of the target – they are looking for trusted access and opportunities. “What concerns me about this incident is not necessarily the size of the power generator that was affected, but how many others may be out there… This particular incident may not have had consequences for the wider grid, but the next one could be different.”

Advertisement. Scroll to continue reading.

He points out, “The UK has thousands of distributed assets increasingly contributing to how our energy system operates. Individually, many may appear insignificant. Collectively, their resilience matters enormously.”

Graeme Stewart, head of public sector at Check Point, warns, “This marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days. That should concern every organization responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat. The far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.”

Attribution, however, remains an important caveat. Public reporting has connected the incident to Iran-linked hackers, but the lack of detailed confirmation from the UK government or the NCSC makes a definitive judgment difficult.

“The attribution of cyber attacks are sometimes obvious. And yet the job of an intelligence professional is to avoid bias and do the work,” commented Robert M. Lee, CEO of Dragos. “People jumping to conclusions on Iran being behind the UK attack, the water attacks in the US, etc. are very susceptible to false flag operations (games) by other countries. It’s probably Iran. But probably isn’t enough in geopolitics. Serious matters require serious work even when hindsight bias would say it’s obvious. Let the intelligence professionals do their work.”

Since the start of the Iran war, Iranian hackers have targeted the critical infrastructure of the US and its allies. Other than Israel, the UK is generally considered to be a major ally of the US. Britain cannot be surprised that it is a target – indeed, the greater surprise is that this appears to be the only known successful Iranian cyberattack to date. Apart from the lack of official information (almost all knowledge is based on a single report in the Telegraph), concern should also focus on the apparent lack of resilience in the hacked power station. Four days to recover in such an important part of the CNI is simply too long. And if the attack is repeatable, and Iran increases such attacks, the UK should brace itself.

Related: US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them

Related: Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

Related: US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

Related: LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers

Related Content

Data Breaches

Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users.

Cybercrime

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.

ICS/OT

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. 

ICS/OT

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Incident Response

The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.

Cybercrime

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version