ConflictClarifier

2026 Iran-Gulf Crisis Tracker
CC
Events Archive
strikeAug 27, 2026

UK’s small power plants face continued cyber risk after Iran-linked hack

Summary

Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged. Officials this week briefed energy bosses on the breach, which is understood to have shut an unnamed small gas power plant for four days last month, and put the industry on alert over the growing cyber threat facing energy infrastructure. However, the government’s own plan to toughen the baseline cybersecurity standards for Britain’s smallest power generators will not be required until the end of 2030, raising concerns over “an unacceptable gamble with our national security”. Official government documents, published this month, call for the industry regulator, Ofgem, to lay out proposals for new baseline cyber resilience requirements for gas and electricity infrastructure by the end of 2027, ahead of implementing new standards by the end of 2030. The Guardian understands that the hack has not altered this timeline. The new requirements would cover the type of small-scale gas plant which is understood to have been successfully attacked by the Iran-linked hackers in the weeks before the government set out its timeline for bolstering the sector’s cybersecurity standards. Reports of the unprecedented cyber hack emerged as the Cabinet Office prepares to urge UK citizens to stock up on tinned food and bottled water to prepare for extreme weather events and potential attacks from hostile states. Calum Miller, the Lib Dems’ foreign affairs spokesperson, said: “Leaving hundreds of small power generators exposed to cyber threats until the 2030s is simply an unacceptable gamble with our national security.” Britain has hundreds of small-scale, unmanned gas plants connected to local power grids which are typically idle for most of the year but can be used to ramp up generation when electricity supplies are squeezed. Although the outage had no impact on the electricity system, the attack has raised concerns about vulnerabilities in locally connected power infrastructure which is not required to meet the same security standards as large-scale power plants and transmission assets. “The government should not have to wait for the lights to go out before taking the security of our energy infrastructure seriously,” Miller said. “They must immediately fast-track these regulations, not leave them until the 2030s. We mustn’t leave an open goal to hostile states at a time of heightened global threats.” The government opened a consultation into the cyber resilience of power generators in March, after it introduced the cyber security and resilience bill to parliament late last year, with a warning that the UK now faces four nationally significant cyber-attacks every week. Michael Shanks, the energy minister, said in the consultation that the UK “needs to keep pace with the current threat landscape”. An industry source familiar with the post-attack industry briefing confirmed reports, which first appeared in the Sunday Telegraph, that the plant was shut down for about four days in one the most successful cyber-attacks on UK energy infrastructure. “We should use it as a warning rather than wait for an incident,” according to Rafael Narezzi, chief executive of Centrii, an energy cybersecurity specialist. “Across the UK energy system we have small, medium and large generation assets, increasingly connected through digital systems, remote access, third parties and operational technology. This particular incident may not have had consequences for the wider grid, but the next one could be different.” “What concerns me about this incident is not necessarily the size of the power generator that was affected, but how many others may be out there,” Narezzi added. “Attackers do not necessarily select their targets according to how many megawatts they generate. They look for vulnerabilities, trusted access and opportunities. “The UK has thousands of distributed assets increasingly contributing to how our energy system operates. Individually, many may appear insignificant. Collectively, their resilience matters enormously.” A government spokesperson said: “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards. “We are alive to growing cybersecurity threats, which is why we also committed to reviewing the cyber resilience requirement for the downstream gas and electricity sector and are driving this work forward through parliament,” they added. Ofgem was also contacted for comment.

Actors involved

Iran

Sources

  • Jillian AmbroseBy Jillian Ambrose

    Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged. Officials this week briefed energy bosses on the breach, which is understood to have shut a

See this event through different lenses

Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.

Compare Perspectives

Community Notes

Community Notes

Loading notes...

Related events

strikeUnverifiedUSIsraelIranProxyRussiaChinaTaiwan
1 source

As the U.S.-Israeli war against Iran reaches the six-month mark, the Islamic Republic retains dangerous options to impose even higher costs on its militarily superior foes. One tactic raises particular concern among former officials and analysts. At a time when Iran has inflicted billions of dollars of damage in its missile and drone attacks against regional military sites and infrastructure and upended global energy markets with its throttling of traffic in the Strait of Hormuz, a dedicated Iranian cyber campaign could strike at the heart of the U.

S. and potentially prove even more disruptive to both national security and everyday life. Recent reports have already linked Iran to hacks in July that shut down a power plant in the United Kingdom and up to 30 water systems across the U.S. "Cyber is tailor-made for Iran’s asymmetric playbook," Frank Cilluffo, a former Department of Homeland Security official who played a lead role in the White House's immediate post-9/11 security overhaul, told Newsweek.

"Tehran does not need to match the United States plane for plane or ship for ship," Cilluffo, now director of Auburn University's McCrary Institute for Cyber and Critical Infrastructure Security, said. "It can look for softer seams in our economy and critical infrastructure, impose costs far from the battlefield, and create uncertainty about when and where the next shoe may drop.

" The War on Data Since the start of the conflict, Iran has already displayed the capacity to supplement its attacks on military and trade logistics with targeting data centers in the Persian Gulf region that serve a similarly crucial role. In the words of Islamic Revolutionary Guard Corps (IRGC) spokesperson Brigadier General Hossein Mohebbi during a conference on Monday, "when we destroy an Amazon data center in Bahrain, it does not mean we destroy a company or a complex, it means that we have destroyed and shattered the brain of the operations processor.

" Cilluffo called this strategy "particularly instructive," as it demonstrated Tehran's awareness of how "data centers are no longer simply commercial facilities, they are increasingly the backbone of our economies, AI capabilities and, in some cases, national security.

" An even more dire scenario he pointed out could see Iran combine its kinetic drone and missile capabilities with an added cyber component, potentially even artificial intelligence, to create simultaneous pressure across physical and digital targets.

Even "a limited disruption," Cilluffo warned, "can be exaggerated and amplified through disinformation and social media to create the perception of a much larger attack." "An adversary does not have to destroy critical infrastructure to achieve strategic effect.

It can turn a tactical disruption into outsized economic, psychological and political consequences," he said. "The mistake would be to think of an Iranian cyberattack as something separate from a wider conflict. Tehran has spent decades learning how to operate asymmetrically across domains," he added.

"Cyber gives it another means to reach beyond the battlefield and bring the consequences of a conflict directly to the homeland." The Roots of Iran's Cyber Revolution While not traditionally viewed as having access to the same resources or capabilities as top U.

S. rivals China and Russia, both of whom have also been implicated in scores of cyber operations carried out against the U.S., Iran has a long history engaging in battle on this front. Tehran has also been a frequent target of cyber infiltration, with one of the first major instances being the infamous Stuxnet computer worm that swept through and degraded or destroyed thousands of systems tied to Iran's nuclear enrichment facilities in late 2009.

The disastrous episode served as an impetus for Iran to develop and hone its own cyber prowess. "Iran has been building their capabilities ever since being on the receiving end of the U.S.-Israeli Stuxnet operation, nearly 15 years ago," Jason Healey, a founding member of the White House's Office of the National Cyber Director and the world's first-ever cyber command, Joint Task Force for Computer Network Defense, told Newsweek.

In 2012, then-Iranian Supreme Leader Ali Ayatollah Khamenei, who was later killed on the first day of the ongoing war after Israel allegedly hacked traffic and CCTV cameras to track leadership movements, ordered the establishment of the Supreme Council of Cyberspace.

And by 2015, the IRGC had formed its own Cybersecurity Command, though the elite force had previously pursued cyber activities through its Center to Investigate Organized Crimes. While the stated mission of the IRGC's cyber wing largely pertains to maintaining internal security, preserving the Islamic Republic's values and defending against foreign foes, U.

S. experts and officials also see an offensive mandate. Newsweek has reached out to a representative of Iran's National Center for Cyberspace for comment. Contacted for comment, a U.S. defense official told Newsweek that, "as a matter of operational security, we do not comment or discuss cyber intelligence, plans, operations capabilities, or effects.

" Lethal Potential In most cases, suspected Iran-affiliated cyber operations are attributed to apparent proxy groups, including the Iranian Cyber Army, first active in 2009 as one of the earliest known groups linked by analysts to Iran. Many more have emerged since, such as those variously designated as APT—or Advanced Persistent Threat—33 (Elfin Team), APT 34 (Helix Kitten), APT 42 (Mint Sandstorm) and MuddyWater.

The latest alleged Iranian attacks on U.S. water systems were not the first of their kind. Iran-tied actors were blamed for earlier cyberattacks against a New York dam in 2013 and Pennsylvania local water authority a decade later, the latter being carried out by a group calling itself CyberAv3ngers.

CyberAv3ngers is one of several actors to have emerged in the wake of the outbreak of the war in Gaza in October 2023. Another known as the Handala Hack Team has taken credit for a number of attacks throughout the nearly three-year Middle East crisis, perhaps most notably wiping the systems of U.

S. medical company Stryker Corporation in March of this year, shortly after the start the of the U.S.-Israeli war against Iran. Even more recently, Iran's semi-official Tasnim News Agency reported Tuesday on an operation by the so-called Cyber Support Front to infiltrate the network of Israeli company Novamill, claimed to be involved in the manufacturing of weapons systems.

Healey, now serving as senior research scholar at Columbia University’s School for International and Public Affairs, warned "someday soon they might succeed with an attack on U.S. infrastructure that disrupts services and maybe even leads to deaths either directly or indirectly (such as by water outages that lead to disruption of hospitals).

" "Even to a modest event, any president might then feel the need to respond militarily and not tolerate it, as has been more the norm," he said. 'Less to Lose' Michael Sulmeyer, professor at Georgetown University's School of Foreign Service who previously served as the Pentagon's assistant secretary for cyber policy and principal cyber adviser, recently outlined in Foreign Policy a number of ways in which China could exploit gaps in local defense infrastructure using AI-enhanced cyberattacks in the event of an escalation over Taiwan.

And he told Newsweek that "much of the same logic could apply to Iran." The most "concerning scenarios" he saw involve not a single massive "cyber Pearl Harbor" strike, but a wave of operations targeting critical infrastructure, either in the U.S. or among regional partners—potentially a combination of both.

In addition to water and power systems other sites of interest include pipelines and factories. Sulmeyer also raised the alarm on the insufficient pace at which the U.S. was adapting to the rapidly evolving capabilities of AI-powered cyberattacks with some systems taking years to properly bring up to date with the current threat landscape.

And while he noted that "the United States and Israel, among others, have significant combat power in cyberspace as well," there is another element that may compound the risk factor in dealing with Iran's cyber corps at a time when the Islamic Republic was fighting what it viewed to be an existential battle.

"Unlike many other nations, leaders in Tehran probably feel they have less to lose when conducting cyber operations for disruptive effect in addition to more traditional reconnaissance work," Sulmeyer said. A Twofold Strategy Already, Iran appears to be quietly scoring gains via a "twofold" strategy described by Nikita Shah, a former U.

K. national security official serving today as senior fellow with the Center for Strategic and International Studies' Intelligence, National Security, and Technology program. The first involves the use of cyber espionage to support kinetic strikes through informing target selection and battlefield damage assessment, while the second constitutes efforts to shape the narrative of the conflict and events surrounding it in Tehran's favor, including with the potential use of AI-enhanced media operations.

"This means using disruptive—but opportunistic—cyberattacks (like hack and leaks, the Stryker incident, or even likely the recent cyberattacks against the U.S. water sector) to cause localized disruption, and then to amplify the impact of those attacks through international media," Shah told Newsweek.

"This serves Iran’s information warfare goals, by provoking and dividing different global audiences, sowing fear and division that it can manipulate over the course of the conflict," she added. And the "unfortunate targets" include U.S. organizations and businesses.

"Iran will want to drag them into the war by targeting them with low-level cyber-attacks," Shah said. "In other words, causing collateral damage to them is the point—Iran will want to wear down domestic U.S audiences in the hope that this will turn U.

S. public opinion against the war, as a means of attrition." Contact Newsweek editors on this story: Edward T. Cummins and Tony Phillips.

Location: Tehran
strikeUnverifiedUSIsraelIran
1 source

The U.S. Central Command (CENTCOM) stated that U.S. forces have cleared Iranian sea mines from the Strait of Hormuz, laid months ago by the Islamic Revolutionary Guard Corps (IRGC). In a video update on X late Thursday, Commander Adm. Brad Cooper termed the achievement a “major milestone,” stating that “international shipping lanes are open and momentum is building.

” He shared a nautical chart of the Strait of Hormuz and said the mine-clearing operation over the months was challenging and involved meticulous efforts of the Navy divers, special operations, and air assets, among other forces. “The circumstances were challenging and dangerous to say the least, but we got the job done,” said Cooper.

In recent months, nearly 1,500 vessels carrying approximately 750 million barrels of crude oil have navigated the waterway, said Cooper. Concurrently, around 50,000 U.S. troops have been enforcing a “highly effective” naval blockade, as a result of which there were ‘zero” oil exports from Iran, he said.

The CENTCOM Commander added that, as part of broader regional efforts, which involve over 20 warships and hundreds of aircraft, U.S. operations have turned back 75 vessels and disabled three non-compliant ones amid escalating tensions with Iran. “No ships have entered or left an Iranian port without our permission, and we have only allowed ships to pass through on humanitarian grounds,” added Cooper.

US Naval Blockade Hits Iranian Oil Exports This development comes against the backdrop of ongoing tensions between the U.S. and Iran, which have been ongoing for the past six months. The U.S. blockade on Iranian oil exports has significantly affected Iran’s oil shipments, according to Kpler data.

Iranian oil loadings fell to 248,000 barrels a day in August, a stark contrast to the 1.85 million barrels of crude a day exported between March and April. Iran’s Mohsen Rezaei told Lebanon’s Al Manar TV that any U.S.-Iran understanding over the Strait of Hormuz must include an end to military operations in Lebanon, Gaza and Syria, along with an Israeli withdrawal from Lebanon and a halt to attacks on Syria.

He stressed that the U.S. must demonstrate its commitment before Iran can rebuild trust. At the time of writing, Brent crude oil futures expiring in October were trading 0.4% lower at $88.17 per barrel, while WTI crude futures expiring in October were trading 0.

5% lower at $83.11 per barrel. Trump in No Rush To Restart Iran Talks President Donald Trump, meanwhile, has adopted a relaxed stance on the timeline for Iran to return to peace negotiations and stated that he is “not in a hurry.” The President stated he has "no time schedule" for Iran to rejoin negotiations aimed at ending the conflict.

The Wall Street Journal reported on Thursday that the Trump administration is not interested in reviving the June memorandum of understanding with Iran. Instead, Trump is waiting to see whether his administration’s economic pressure campaign against Tehran will succeed.

Disclaimer: This content was partially produced with the help of AI tools and was reviewed and published by Benzinga editors. Photo courtesy: Shutterstock © 2026 Benzinga.com. Benzinga does not provide investment advice. All rights reserved. To add Benzinga News as your preferred source on Google, click here.

Location: Tehran
strikeUnverifiedUSIsraelIran
1 source

Reporting characterizes the ongoing US-Iran conflict as a stalemate, noting that while both sides continue exchanging strikes, shipping in the Strait of Hormuz has significantly slowed and oil prices remain elevated. While unverified claims suggest Iran's military infrastructure is severely damaged, analysts indicate that Tehran retains operational capability and strategic leverage over global energy markets.

Location: Iran