Iran shut down a British power plant for four days in an unprecedented cyber attack, The Telegraph has revealed.
It is thought to be the first time that hackers affiliated to the Iranian regime have succeeded in closing down such a facility in the UK, and is believed to be the most successful cyber attack of its kind.
The Telegraph understands that the incident took place at the same time as a series of attacks on US water infrastructure last month, which affected 12 states and caused concern in the White House.
British officials refused to be drawn on which power plant had been affected, citing security concerns, but it is understood that the facility was disabled for four days while staff fought to bring it back online.
It is understood that the plant affected was relatively small and that the outage had no impact on the UK’s wider power supply or energy generation.
In response, the UK government briefed the chief executives of power companies and wrote to businesses with advice, direction and next steps.
The incident is understood to have been reported to the country’s National Cyber Security Centre (NCSC), a public-facing branch of the GCHQ spy agency that issues advice to companies on keeping national infrastructure safe from foreign threats.
British and American intelligence agencies have repeatedly warned of the risk posed by hackers from Russia, China, Iran and North Korea, which bombard critical national infrastructure and government agencies with attacks on a daily basis.
Major incidents have previously brought down NHS systems, schools and commercial manufacturing facilities, including production lines at Jaguar Land Rover.
Foreign hacking groups have also stolen customer information from retail businesses, including attacks last year, and voter records from the UK Electoral Commission.
However, no hacker is thought to have ever succeeded in bringing a British power plant to a standstill, despite warnings that attacks on national infrastructure are commonplace.
It is unlikely that the attack against the UK power plant was intended to inflict genuine harm on civilians, and is not thought to have been widely noticed by the public.
But it is possible that the incident was designed to prove that hackers linked to Iran’s Islamic Revolutionary Guard Corps could gain access to systems in the UK and close down sensitive infrastructure sites.
There are dozens of small-scale power plants across Britain connected to the grid.
Many of them are gas-fired and only used for a few hours a week, for example when wind speeds are low and extra energy is needed.
A four-day outage at such a facility would not affect the wider grid. Some factories and other facilities such as hospitals also have their own separate power generators.
The US hacks affected dozens of wastewater treatment plants, causing flooding and a loss of pressure from taps, and forcing some authorities to advise customers to boil their water before drinking it.
The first reports of an incident emerged in Minnesota on July 26, followed by a series of similar security breaches in Michigan, Georgia, South Dakota and New Jersey.
The FBI attributed the incidents to “malicious cyber actors”, but US government sources later confirmed to media outlets that the threat was likely to have originated in Tehran.
Iran has stepped up its cyber attacks on Western countries in the wake of the conflict in the Middle East, and especially since the US and Israel began airstrikes in February.
Suspected Iranian attacks have been reported in Germany, Poland, Finland, Belgium and Albania, although Israel and other Middle Eastern countries are the most common targets.
In March, the NCSC advised British organisations to review their security approaches in light of the conflict, while Richard Horne, the agency’s chief executive, said in June that it had dealt with more than 200 attacks on critical national infrastructure in the previous year.
The NCSC does not routinely acknowledge individual incidents, and declined to comment on the attack on a UK power plant.
Experts have long warned that the UK is unprepared for the scale of the threat of malicious cyber attacks from foreign adversaries, and the intelligence and security committee, which oversees spying agencies, reported last year that the chance of an Iranian cyber attack on British infrastructure was “unlikely”.
However, the committee also said that cyber warfare was a “significant area of asymmetric strength” for Iran, which spends tens of millions of dollars on hacking groups, each containing hundreds of people.
An official risk assessment by the UK Cabinet Office, published last month, found the risk of a serious and successful cyber attack against domestic infrastructure was between 5pc and 25pc, but warned that “AI can automate the process of launching cyber attacks, making them faster, more efficient and lower the barrier for entry”.
A UK government source said: “We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near. It’s a very small-scale site, less than a rounding error compared to grid capacity.
“The UK has a highly resilient energy system.
We work closely with the energy sector to protect infrastructure and ensure the highest security standards.
“This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.