A cyberattack linked to Iranian threat actors forced a British power plant offline for four consecutive days in July, reportedly marking the first successful cyber incident to disrupt a UK energy-generation facility completely.
This incident, first reported by The Telegraph, affected a small-scale electricity generator rather than a major power station. The UK government emphasized that the attack did not threaten the national grid or disrupt broader electricity supplies.
Hackers Shut Down UK Power Plant
A spokesperson for the Department for Energy Security and Net Zero (DESNZ) stated that the event impacted a small-scale energy generator and added that the UK operates a highly resilient energy system.
Officials noted that the affected facility accounted for only a negligible proportion of national generation capacity and fell below the reporting threshold for major regulated operators.
Despite the limited immediate impact, the incident has raised concerns across the UK energy sector because attackers successfully forced the energy facility to shut down entirely.
Security analysts view this disruption as a significant proof-of-concept operation by groups linked to Iran’s Islamic Revolutionary Guard Corps (IRGC).
The objective may have been strategic signaling rather than widespread disruption; by turning off a power generator, the attackers could demonstrate their ability to penetrate operational technology environments and influence industrial processes within UK critical infrastructure.
The cyberattack occurred amid rising geopolitical tensions between London, Washington, and Tehran. It also coincided with warnings from US agencies, including the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and Environmental Protection Agency (EPA), about Iran-aligned actors targeting water-sector organizations in the United States.
This timing has heightened concerns that Iranian-linked groups may be pursuing a broader campaign against Western critical infrastructure. These campaigns often target exposed remote-access services, internet-facing industrial systems, poorly segmented IT and operational technology (OT) networks, and third-party suppliers.
The National Cyber Security Center (NCSC), part of GCHQ, has not publicly confirmed the technical details of the reported attack on the power plant or identified the affected organization.
No outages were reported by regulated operators of major UK power stations, which supports the government’s assessment that the wider electricity system remained unaffected.
Following the incident, DESNZ reportedly briefed energy sector chief executives and distributed written cybersecurity guidance to operators. Officials are reportedly updating cybersecurity regulations governing the sector.
This event underscores the risk posed by state-aligned threat actors targeting industrial control systems. Even attacks against small generators can test defensive response processes, expose weaknesses in OT network segmentation, and provide adversaries with intelligence that could be useful for future operations against higher-value targets.
NCSC chief executive Richard Horne has warned that the agency is handling at least four nationally significant cyberattacks each week, with the threat likely to increase if geopolitical tensions escalate further.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

