ConflictClarifier

ردیاب بحران ایران-خلیج فارس ۲۰۲۶
CC
Events Archive
strikeAug 23, 2026

Report: Iranian hackers shut UK power plant for four days in unprecedented cyberattack

Summary

Hackers linked to Iran shut down a British power plant for four days in what is believed to be the first successful Iranian cyberattack to force a UK electricity-generating facility offline, The Telegraph reported. The attack did not disrupt Britain's broader electricity supply because the facility was relatively small, according to the report. But its apparent success has raised concern among British officials because it demonstrated that hackers affiliated with Tehran may be capable of penetrating and disabling sensitive energy infrastructure. British authorities have declined to identify the plant, citing security concerns. The Telegraph reported that staff spent four days working to restore the facility after the breach. The incident occurred around the same time as a wave of cyberattacks against U.S. water infrastructure that affected facilities in 12 states last month and prompted concern at the White House, the newspaper reported. Following the British breach, the government briefed energy company executives and sent businesses guidance on cybersecurity precautions and their next steps, according to The Telegraph. The incident was also reported to Britain's National Cyber Security Centre, or NCSC, the public-facing arm of the GCHQ intelligence agency responsible for helping organizations defend critical infrastructure against cyber threats. While cyberattacks against British institutions are frequent, The Telegraph said no previous hacking operation is believed to have successfully brought a UK power plant to a standstill. The plant targeted in the attack was small enough that losing it for several days had no meaningful effect on national generating capacity. Britain has dozens of smaller power stations connected to the grid, including gas-fired facilities that may operate only intermittently when additional electricity is needed. A British government source sought to play down the effect on the grid while acknowledging the incident. “We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near,” the source told The Telegraph. “It’s a very small scale site, less than a rounding error compared to grid capacity.” The purpose of the attack remains unclear. The Telegraph reported that it was unlikely to have been designed to cause significant harm to civilians and appears to have attracted little public attention at the time. One possibility, according to the report, is that the operation was intended as a demonstration of capability, showing that hackers linked to Iran's Islamic Revolutionary Guard Corps could penetrate British systems and shut down sensitive infrastructure. Attacks on US water systems The British incident coincided with cyberattacks on dozens of wastewater treatment facilities across the United States. Those attacks caused flooding and drops in water pressure in some locations, while some authorities told residents to boil water before drinking it. The first known incident was reported in Minnesota on July 26, followed by breaches in states including Michigan, Georgia, South Dakota and New Jersey, according to The Telegraph. The FBI initially attributed the incidents to “malicious cyber actors.” U.S. government sources subsequently told media outlets that the activity was believed to have originated in Tehran. Iran has intensified cyber operations against Western targets since the escalation of the Middle East conflict and particularly since U.S. and Israeli airstrikes began in February, The Telegraph reported. Suspected Iranian attacks have since been reported in several European countries, including Germany, Poland, Finland, Belgium and Albania, although Israel and other countries in the Middle East remain among the most frequent targets. British authorities had already been warning organizations to prepare for such activity. In March, the NCSC urged companies to reassess their cybersecurity measures because of the conflict. Richard Horne, the agency's chief executive, said in June that the NCSC had handled more than 200 attacks against critical national infrastructure during the previous year. The agency declined to comment specifically on the power plant attack, in keeping with its policy of generally not discussing individual incidents. Growing threat to critical infrastructure Britain and the United States have repeatedly warned that state-linked hackers from Iran, Russia, China and North Korea target government networks and critical infrastructure on a regular basis. Previous major cyber incidents in Britain have disrupted NHS systems, schools and manufacturing operations. Hackers have also targeted retailers and government-related databases, including an attack that compromised Electoral Commission voter records. But successfully disabling an electricity-generating facility represents a potentially more serious threshold because of the implications for critical national infrastructure. An assessment by Britain's parliamentary Intelligence and Security Committee last year described Iranian cyber warfare as a “significant area of asymmetric strength,” according to The Telegraph. Iran is believed to spend tens of millions of dollars supporting hacking groups involving hundreds of personnel. A separate Cabinet Office risk assessment published last month put the likelihood of a serious and successful cyberattack on domestic infrastructure at between 5% and 25%. The assessment also warned that artificial intelligence could increase the scale and accessibility of such operations by automating attacks and allowing them to be carried out more rapidly and efficiently. Despite the breach, the British government stressed that the country's electricity network had not been endangered. “The UK has a highly resilient energy system,” a government spokesman told The Telegraph. “We work closely with the energy sector to protect infrastructure and ensure the highest security standards.” “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.”

Actors involved

USIsraelIranRussiaChina

Sources

  • Ynet GlobalBy Ynet Global

    Hackers linked to Iran shut down a British power plant for four days in what is believed to be the first successful Iranian cyberattack to force a UK electricity-generating facility offline, The Telegraph reported. The attack did not disrupt Britain's broader electricity supply b

See this event through different lenses

Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.

Compare Perspectives

Community Notes

Community Notes

Loading notes...

Related events

strikeUnverifiedUSIranRussiaChina
1 source

Cyber attack shut down UK power plant – Telegraph A small-scale British power plant was taken offline because of a cyber attack, with UK authorities blaming an Iranian-linked hacking group, The Telegraph reported on Saturday. In the UK, dozens of small-scale power plants are connected to the national grid, many of them gas-fired facilities that operate for just a few hours a week.

The newspaper did not specify which facility was targeted but noted that it was out of operation for four days in July. The authorities reportedly notified the National Cyber Security Centre, a public-facing branch of the Government Communications Headquarters, held emergency briefings for energy company executives and sent businesses guidance on strengthening security measures.

According to The Telegraph, the incident coincided with a series of cyberattacks targeting water infrastructure in the US that affected facilities in 12 states. Earlier this month, CBS News cited sources as saying that more than 30 community water systems had been impacted and that the attacks might be linked to Iran-backed hackers.

Some utilities reportedly lost critical remote-control capabilities, forcing operators to switch to manual mode. In several cases, the hackers gained remote access to pumps, valves, and water pressure. Western intelligence agencies have repeatedly claimed that critical national infrastructure and government bodies face a constant threat from hackers in Iran, North Korea, China, and Russia – allegations that the authorities in each country have dismissed.

Moscow says that the West habitually cites the supposed threat of external aggression to justify a massive military buildup and the development of offensive cyber capabilities.

strikeUnverifiedUSIsraelIranRussia
1 source

Cyber hackers linked to Iran shut down a UK power plant for four days. The incident, which occurred in July, involved an unidentified small-scale energy generator, according to The Telegraph. Hackers unlikely had civilian harm in mind when targeting the power plant, though it is reportedly the first time Iran-linked crooks knocked one offline.

The National Cyber Security Centre, part of the spy agency GCHQ which investigates attacks on infrastructure, declined to comment as it does not routinely acknowledge individual incidents. The power grid was never at risk and the incident had no impact on energy production, the Department for Energy Security and Net Zero told Metro.

Sign up for all of the latest stories Start your day informed with Metro's News Updates newsletter or get Breaking News alerts the moment it happens. Department officials briefed energy bosses and wrote to companies with advice, direction and next steps following the shutdown.

A government spokesperson added: ‘The UK has a highly resilient energy system. ‘We work closely with the energy sector to protect infrastructure and ensure the highest security standards. Could hackers target anything else in the UK? Security experts have long warned that a cyber attack by a foreign country during a time of war isn’t just the stuff of cheap Hollywood films.

Fears of Iranian-linked cyber attacks have been high since the US and Israel launched a deadly attack on Iran in February, igniting a war. Factories are easy targets for cyber attacks, Steffan Roxrud Thorvaldse, CEO of Qbee, a device management platform, told Metro.

‘Modern factories now operate as “smart” environments where everything is connected, from sensors and cameras to robotics and control systems,’ he said. ‘That means more ways in for attackers.’ Attackers can gain entry by slipping into security holes in online systems, such as a CCTV camera that uses out-of-date software.

‘From there, attackers can move through networks and potentially interfere with systems that control real-world operations, like factory machinery and production lines,’ Thorvaldse added. Some experts worry that ‘Iranian hacktivists’, groups which either have ties to or are sympathetic to the regime, could strike.

Richard Ford, CTO of the cybersecurity specialist Integrity360, said: ‘It’s impossible to say what companies could be next and whether any will be in the UK, but the chances of it will depend on the UK’s perceived involvement in the war. ‘Although, as with the war, it is not just the US and Israel being targeted but also their partners and allies.

’ Other experts worry that hacking groups could also be posing as Tehran-affiliated to stir up tensions. Or they are using the Iran war to pursue their own agendas, such as what a pro-Russian group did by prying open CCTV footage of an Ipswich go-kart track in March.

‘#TimeOfRetribution,’ the group said in a Telegram post at the time, seen by Metro. Hacktivists can be hired on the dark web, a shady, heavily encrypted corner of the internet away from prying eyes, to knock out websites. One common – and cheap – hack offered is a distributed denial of service (DDoS), which brought down a massive chunk of the web last November.

Computer vandals jam a website with so many requests that it buckles under the load and becomes unresponsive. Despite these concerns, experts who specialise in tracking Iranian hacking groups have seen little activity. This was to be expected. The Intelligence and Security Committee, which oversees spy agencies, said last year that while Iran spends millions of dollars on hacking groups, it’s ‘unlikely’ they’d break into British facilities.

Trending Now The risk of a successful cyber attack against UK infrastructure is between five and 25%, the Cabinet Office said in July. Still, Ford says it’s vital the government is prepared for cyber attacks, which officials routinely stress that they are.

‘The worst case, which is less trivial to launch and successfully orchestrate, would be a breach of Critical National Infrastructure (CNI) such as electricity, water supply, health services and food supply, and that could have a myriad of effects and be the highest impact felt by Britons,’ Ford said.

‘M&S is a very good example of a cyber attack,’ he added of the Easter breach last year, ‘particularly in terms of severity and impact where shelves were left bare and customers unable to place orders.’ Get in touch with our news team by emailing us at webnews@metro.

co.uk. For more stories like this, check our news page. MORE: OpenAI’s rogue robot tried to hack into other companies – could your data be next?

strikeUnverifiedUSIsraelIranRussiaChina
1 source

Hackers linked to Iran have been blamed for a cyber-attack that caused a British power plant to be temporarily shut down. The incident involved a small-scale energy generator, according to the UK government and at no point was there there risk to the wider energy system.

However, it marks an apparent escalation in the threat posed by Iran after the UK said it had given permission for the US to launch “defensive” operations against Tehran from British bases. The power plant was shut down for four days as a result of the attack last month, according to the Sunday Telegraph, which first reported it.

A spokesperson for the Department for Energy Security and Net Zero said: “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The UK has a highly resilient energy system.

We work closely with the energy sector to protect infrastructure and ensure the highest security standards.” The National Cyber Security Centre (NCSC), which deals with attacks on critical infrastructure, is understood not to have received any reported outages from regulated operators of power stations.

Hostile states such as Russia, China and Iran are increasingly targeting systems behind the UK’s key services, according to a warning this year from Richard Horne, the NCSC’s chief executive. The government said last month the UK was “ready to defend itself” after Iran’s military warned any bases being used by the US were “legitimate targets”.

The UK has allowed the US to launch so-called defensive operations from British bases hosting American planes since the start of its war on Iran but has refused to help in offensive operations. That policy has not been altered by the new prime minister, Andy Burnham, who was notified last week that a decision had been made to extend the agreement with the US.

Iran’s Islamic Revolutionary Guard Corps (IRGC) said last month that “any base used for aggression against Iranian territory constitutes a legitimate target for our forces”. Iran has been accused for years of carrying out cyber-attacks on various countries, including in relation to a massive power outage in Turkey in 2015 and several possible breaches of Israeli government websites in 2022.

US government security agencies issued a warning earlier this year of cyber-attacks on critical infrastructure by hackers linked to the IRGC. The US has alleged that an Iran-affiliated group known as “CyberAv3ngers” carried out a campaign against it in 2023 that compromised at least 75 devices in multiple infrastructure sectors.

strikeUnverifiedUSIran
1 source

UK power plant 'shut down for four days' after major Iran-linked cyber attack The incident took place in July, at the same time as a series of attacks on US water infrastructure which sparked worry in the White House and affected 12 states A power plant in Great Britain was forced to close for four days after a cyber attack by Iran-linked hackers, it has been revealed.

According to reports, the facility was disabled "while staff fought to bring it back online" after the attack last month - the exact location of the site has not been revealed due to security reasons. It is, however, understood that the plant affected was not one of the biggest sites in the country, according to the Telegraph.

Due to the relatively small nature of the plant, the outage had no impact on the UK’s wider power supply or energy generation. This has been confirmed by the Government, which has described the UK's energy system as 'highly resilient. The incident took place in July, at the same time as a series of attacks on US water infrastructure - those attacks affected 12 states and caused concern in the White House.

In response, the Government briefed the chief executives of power companies and wrote to businesses with advice, direction and next steps. A Government source told the Telegraph: “We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near.

It’s a very small scale site, less than a rounding error compared to grid capacity.” A Government spokesman said: “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.

“This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.

Location: Tyre