A power plant in the United Kingdom was reportedly shut down for four days by Iran-linked hackers, an incident described as the most successful cyberattack of its kind against UK energy infrastructure. The outage, which occurred concurrently with attacks on water infrastructure across 12 U.S. states, did not impact the UK's wider power supply due to the plant's small size.
British officials have not publicly identified the affected power plant, citing security concerns. Staff worked for four days to restore operations. Following the incident, the government issued guidance to power companies and businesses on how to respond to similar threats. The National Cyber Security Centre (NCSC), a division of GCHQ responsible for protecting UK critical infrastructure, was notified but declined to comment on the specific event.
The attack is believed to be the first confirmed instance of hackers affiliated with the Iranian regime successfully disabling a UK power facility. While the outage did not affect the broader grid, the likely intent behind the attack was to demonstrate the capability of Iran's Islamic Revolutionary Guard Corps-linked hackers to access and disrupt UK infrastructure at will. This four-day shutdown of a small generator, unnoticed by the general public, is considered a successful proof of concept from the attackers' perspective.
This incident follows a surge in suspected Iranian cyber operations targeting Western countries since February, coinciding with air strikes by the U.S. and Israel. Reports of such operations have emerged from Germany, Poland, Finland, Belgium, and Albania, with Israel and other Middle Eastern nations remaining frequent targets. In March, the NCSC advised British organizations to reassess their security posture in light of the escalating conflict. NCSC chief executive Richard Horne stated in June that the agency had addressed over 200 attacks on critical national infrastructure in the preceding year.
The timing of this attack is notable, given previous assessments of the UK's preparedness for cyber threats. Last year, the intelligence and security committee, which oversees UK spying agencies, deemed the likelihood of an Iranian cyberattack on British infrastructure as "unlikely." However, a Cabinet Office risk assessment published last month placed the probability of a serious and successful cyberattack on domestic infrastructure at between five and twenty-five percent. That same document also warned that artificial intelligence is making attacks faster, cheaper, and more accessible to a wider range of actors.
A government source downplayed the significance of the incident, stating that the affected site was "nowhere near" the threshold for important generators legally required to report cyber activity. The source characterized it as a "very small-scale site, less than a rounding error compared to grid capacity." A government spokesman reiterated that the UK possesses a robust and resilient energy system and that the incident never jeopardized the wider power network.
The concurrent U.S. water infrastructure attacks affected dozens of wastewater treatment plants across 12 states, leading to issues such as flooding and loss of water pressure, prompting boil water advisories in some areas. The initial reports surfaced from Minnesota on July 26, followed by similar breaches in Michigan, Georgia, South Dakota, and New Jersey. The FBI attributed these incidents to "malicious cyber actors," with U.S. government sources later confirming that the threat likely originated from Tehran.






