CyberSecurityNews

Iran-Linked Hackers Force UK Power Plant Offline in Unprecedented Four-Day Cyberattack


A cyberattack attributed to hackers linked to Iran forced a British power plant offline for four consecutive days last month, marking what officials describe as the first successful attack of its kind against UK energy infrastructure.

The incident, first reported by The Telegraph, has raised fresh alarm over the vulnerability of critical infrastructure amid heightened tensions between the UK, US, and Tehran.

According to the UK government, the affected facility was a small-scale energy generator, and officials have stressed that at no point was there any risk to the broader national grid.

A spokesperson for the Department for Energy Security and Net Zero (DESNZ) said the incident “impacted a small-scale energy generator” and reiterated that “the UK has a highly resilient energy system,” adding that the government works closely with the energy sector to maintain the highest security standards.

A government source went further, telling reporters that the targeted site was “less than a rounding error compared to grid capacity” and fell well below the legal thresholds that require significant generators to report cyber incidents.

Despite the reassurances, security analysts view the attack as a notable escalation. It is believed to be the first time hackers affiliated with the Iranian regime have successfully forced a UK power facility to shut down entirely, and it comes shortly after London granted the United States permission to launch defensive military operations against Iran from British bases.

Hackers Force UK Power Plant Offline

The attackers’ likely goal was not to cause widespread harm but to demonstrate that groups linked to Iran’s Islamic Revolutionary Guard Corps can penetrate UK infrastructure and disable it at will, calling the incident a “successful proof of concept” even though it went largely unnoticed outside the energy industry.

The outage reportedly occurred in July, around the same time that US agencies, including the FBI, CISA, and the EPA, issued warnings about Iran-linked actors targeting water utilities across multiple states, according to The Telegraph report.

That parallel timing has fueled speculation that Tehran-affiliated groups are conducting a broader, coordinated campaign against Western critical infrastructure rather than isolated, opportunistic intrusions.

The National Cyber Security Center (NCSC), which is responsible for defending the UK’s critical infrastructure and operates under GCHQ, has not publicly confirmed details of the specific incident and did not identify the facility involved, citing security concerns.

However, it is understood that no outages were formally reported by regulated operators of major power stations, reinforcing the government’s position that the wider electricity supply was never threatened.

Following the incident, DESNZ briefed energy sector chief executives and issued written guidance to companies on strengthening their defenses, and officials have indicated that cybersecurity regulations for the sector are now being updated.

GCHQ’s NCSC chief executive, Richard Horne, has separately warned that the agency now handles at least four “nationally significant” cyberattacks every week, cautioning that such incidents could increase sharply if the UK becomes more directly entangled in the wider Iran conflict.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link