A small-scale power plant in the United Kingdom was shut down for four days due to a suspected cyberattack, which government officials confirmed on Monday. While the UK government has not formally attributed the incident, it is believed to be linked to Iran. Authorities emphasized that the wider energy system was never at risk, describing it as "highly resilient."
UK Energy Minister Michael Shanks stated that following the incident, his department briefed energy CEOs and provided additional security advice to companies. The specific power station affected was not disclosed by government officials.
This incident is believed to be the first disruptive Iranian cyberattack of its kind in the UK. It occurred around the same time as a series of digital intrusions targeting American water utilities across 12 states. In late July, suspected Iranian cyber operatives disrupted over 30 water facilities in Minnesota, with similar reports emerging from at least 11 other US states.
While US state and federal officials have not formally attributed these water system hacks, private-sector threat analysts strongly suspect Iran is responsible. These breaches are seen as a direct response to the ongoing conflict in the Middle East.
The American utility cyberattacks primarily involved internet-connected programmable logic controllers (PLCs). Federal agencies recently issued a warning that attackers are now employing AI-generated exploitation scripts to breach internet-exposed Siemens S7 Series PLCs in various critical facilities, including those in water, manufacturing, and energy sectors.
Experts suggest that this activity appears to be a continuation of the same pattern of Iran-affiliated actors targeting PLCs. These devices are fundamental to essential health, safety, and critical infrastructure across society, making them attractive targets for adversaries. The use of AI-generated scripts represents an active and evolving threat, not merely a theoretical risk.






