Hackers linked to Iran reportedly forced a small British power generator offline for four days in July, marking an apparent escalation in cyber threats against the U.K. energy sector, according to reports by the BBC and The Telegraph. The affected facility was not identified, but the U.K. government said it was a small-scale generator and that the incident posed no risk to the wider electricity system. No power outages were reported, and officials said the national energy network remained resilient.
The incident prompted the U.K. government to brief energy industry executives on Monday on measures to strengthen protections for critical infrastructure. Energy Minister Michael Shanks said the government and industry were taking the incident seriously and working with regulators and the National Cyber Security Centre to assess the threat.
Officials have not formally attributed the attack to Iran, while the Iranian Embassy in London did not immediately respond to requests for comment.
Back in June, Richard Horne, NCSC CEO, warned that hostile states are driving the majority of cyber activity targeting the country’s critical infrastructure, saying around 75% of attacks can be linked to state actors. Speaking at the Royal United Services Institute (RUSI) Annual Security Lecture, Horne said the agency had managed more than 200 cyber incidents affecting critical national infrastructure and its wider ecosystem over the past year. He said adversaries, including those from Russia, China and Iran, are increasingly focusing on systems that underpin essential services, underscoring scale and persistence of the threat facing the U.K.’s most sensitive networks.
Noting that a four-day outage at a U.K. generation site is still significant even when the lost capacity, as in this case, is small, Ric Derbyshire, principal security researcher at Orange Cyberdefense, wrote in an emailed statement that the incident creates a second-order cognitive effect across wider society by showing that U.K. energy infrastructure can be reached and disrupted through cyber activity.
“That perception can shape how people view the resilience of critical infrastructure and potentially undermine public trust and confidence,” Derbyshire assessed. “The incident also sits within a wider increase in hostile-state and state-aligned activity against national infrastructure. The NCSC has warned repeatedly about this trend and about the growing use of cyber operations as part of wider geopolitical pressure.”
He added that “While the actors and specific technology affected in this incident are not confirmed, the shape of the event seems to follow a broader pattern of actors chasing the metaphorical cyber-dragon for bigger and more shocking impacts, including disruption of OT within CNI. If this escalation continues, defenders should expect more actors to pursue overt disruption of physical infrastructure.”
Rob Demain, CEO of e2e-assure, wrote in a statement that at this time, “we don’t know much about the attack beyond that the power plant experienced downtime, which could have been a direct effect of the attack, part of the defensive response, or a combination of both. What it does demonstrate is that state-linked actors have both the intent and capability to target relatively ordinary industrial technology and are establishing access within the technology underpinning CNI that could potentially be used to cause disruption in future conflicts.”
The conclusion, however, Demain cautioned, should not be that Iranian hackers have demonstrated an ability to switch off Britain’s whole electrical grid, but it does highlight the challenges the industry is facing. The electricity system is becoming increasingly distributed and, while one asset is of little consequence, a weakness that is repeated across hundreds of similar assets could compound to a significant problem due to the technology and suppliers the grid relies on.
He goes on to highlight that how they got into the powerplant isn’t currently clear, but it doesn’t necessarily have to have been a sophisticated attack. “CNI is vulnerable to all sorts of basic security challenges: exposed internet-facing devices, compromised remote access credentials, vulnerable gateways, or compromised third-party accounts.”
“The challenge with securing operational technology (OT) is that it runs on legacy software that can’t be easily patched remotely, and operators always have to weigh up the operational and safety consequences of intervening as an outage or downtime could threaten safety,” Demain pointed out. “Replacing legacy systems takes time and has to be done with a lot of thought and care, but operators can’t accept exposure in the meantime. They must balance moving carefully when changing the plant, but quickly when reducing the risk around it. Immediate steps can be as simple as quickly identifying what is internet-facing, removing unnecessary remote-access paths, disabling dormant supplier accounts, rotating weak or compromised credentials, and restricting who can reach operational systems.”
The disclosure comes amid reports of Iranian-linked cyber activity targeting critical infrastructure in the U.S., including water systems, raising concerns about the potential for similar attacks against Western energy and industrial systems. U.S. agencies have warned that threat actors are targeting Siemens S7 Series PLCs across critical manufacturing, energy, water, chemical, food and agriculture, and commercial facilities. NSA, CISA, FBI, DOE and EPA said exploitation could disrupt industrial processes and trigger safety incidents, equipment damage, data compromises and cascading impacts across interconnected systems.


