Iran-linked cyberattack shut down a UK power plant
Developed over time first seen 2 months ago
A suspected Iran-linked cyberattack knocked a small UK power plant offline for four days, in what is believed to be the first disruptive Iranian cyberattack of its kind on British soil. A UK government spokesperson confirmed the incident to The Register, describing the affected site only as a "small-scale energy generator" and stressing that there was "at no point" any risk to the wider energy system, which it called "highly resilient." Energy Minister Michael Shanks said his department briefed energy company CEOs and issued fresh security advice following the breach, though officials have not named the plant or formally attributed the attack to any state or group.
The incident, first reported by The Telegraph, came amid a wider pattern of suspected Iranian intrusions into critical infrastructure. In late July, suspected Iranian operatives disrupted more than 30 water facilities in Minnesota, with similar attacks subsequently reported across at least 11 other US states, largely via internet-connected programmable logic controllers; private threat analysts have said Iran is "almost certainly" behind these breaches as a response to the Middle East conflict, though this too remains unattributed by officials. Days before the UK plant hack came to light, US federal agencies including the FBI warned that attackers are increasingly using AI-generated exploitation scripts to target internet-exposed Siemens S7 PLCs at water, manufacturing and energy sites, calling it "not a theoretical risk" but "an active threat" linked to the same suspected Iranian campaign.
- Suspected Iran-linked hack shut a small UK power plant for four days
- No risk to wider UK energy system, government says; attack unattributed
- Follows similar suspected Iranian hacks on US water utilities in 12 states
New here? Start with this
Suspected cyberattacks linked to Iran have hit critical infrastructure on both sides of the Atlantic in recent weeks, with a small UK power generation site forced offline and dozens of water facilities across the United States disrupted. These are the kinds of systems that keep essential services like electricity and water running behind the scenes, often controlled by industrial computer equipment that can be vulnerable if connected to the internet.
In this case, UK officials have confirmed that a small-scale energy generator, not a major power station, was taken offline, and have said there is no threat to the wider electricity network. No formal attribution to Iran has been made, and the affected site has not been publicly named, though the incident is thought to be the first of its kind in Britain.
This matters because it points to a broader pattern of state-linked groups probing infrastructure that ordinary life depends on, using automated tools to find and exploit weak points in industrial control systems. Governments and utility companies are now being urged to review their defences, since even small, isolated incidents can signal wider vulnerabilities across a sector.
More coverage
Business Cybersecurity Government Markets Middle East Politics Technology UK World