Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Iran-linked hackers shut down a UK power plant for four days in July 2026.
Summary
Iran-linked hackers successfully disrupted a British power plant for four days in July 2026, raising concerns about the resilience of the UK's distributed energy infrastructure. While the specific plant was not identified, the incident highlights the potential for repeatable attacks and the challenges in recovery, prompting experts to question the preparedness of smaller operators and the broader implications for national security.
Full text
Iran-linked hackers managed to shut down a British power plant for four days in July 2026. The story was broken by the Telegraph newspaper on August 22, 2026. That it took so long to become public knowledge immediately says two things. Firstly, it was not a major power plant since the effect would have been immediately noticed, and secondly, the authorities wished to keep news of the attack as low key as possible. Other newspapers (for example the BBC, the Guardian and the Financial Times) have since published their own stories, largely based on the Telegraph account. There has been virtually no information coming from the expected official sources, such as the NCSC. The BBC report comments, “While the Western cyber-security world is braced for attacks either from the state [of Iran] or hackers linked to the state as a result of its conflict with the US this year, there has been little activity so far.” This last point is clearly wrong. Since the outbreak of the war with US / Israel, Iran affiliated cyber groups have attacked multiple targets in the US (water, critical infrastructure and military-linked assets), Israel (military, government, energy, healthcare, and more), GCC targets in UAE, Bahrain, Kuwait, Qatar, Saudi Arabia, and Europe (Cyprus, Romania and now Britain). This does not equate to ‘little activity so far’, so the expansion into the UK should not be downplayed. And, in general, cybersecurity experts are not downplaying it. “The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption. That raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?”, asks Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress. A related question worth asking is whether Iranian hackers are probing UK defenses for increased aggression – and is this attack repeatable. “The loss of a single facility like this can be well managed and as reported, doesn’t constitute a major risk to stability, but these are often very repeatable attacks that could be deployed at scale,” posts Phil Tonkin, field CTO at Dragos, on LinkedIn. Rafael Narezzi, CEO of Centrii, has a similar concern. He points out that attackers don’t worry about the size of the target – they are looking for trusted access and opportunities. “What concerns me about this incident is not necessarily the size of the power generator that was affected, but how many others may be out there… This particular incident may not have had consequences for the wider grid, but the next one could be different.”Advertisement. Scroll to continue reading. He points out, “The UK has thousands of distributed assets increasingly contributing to how our energy system operates. Individually, many may appear insignificant. Collectively, their resilience matters enormously.” Graeme Stewart, head of public sector at Check Point, warns, “This marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days. That should concern every organization responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat. The far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.” Since the start of the Iran war, Iranian hackers have targeted the critical infrastructure of the US and its allies. Other than Israel, the UK is generally considered to be a major ally of the US. Britain cannot be surprised that it is a target – indeed, the greater surprise is that this appears to be the only known successful Iranian cyberattack to date. Apart from the lack of official information (almost all knowledge is based on a single report in the Telegraph), concern should also focus on the apparent lack of resilience in the hacked power station. Four days to recover in such an important part of the CNI is simply too long. And if the attack is repeatable, and Iran increases such attacks, the UK should brace itself. Related: US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them Related: Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Related: US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices Related: LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Surveillance – Everything You Wanted to Know, But Were Afraid to AskCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOWAI-Driven Vulnerability Surge Breaks the Traditional Patching ModelStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to RedemptionStealthium Targets Security Blind Spots in AI Accelerators and Neo-CloudsThe Fourth Battlefield: The Growing Role of Cyber Operations in Global ConflictCISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout Latest News Rethinking Application Security for the AI EraTikTok Reaches $400 Million Settlement With US Justice Department Over Children’s PrivacyAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightFormer NSA Director Paul Nakasone Launches National Security Advisory FirmIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused BugEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiNew Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveVensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.WISeKey has appointed Alexander Hirsch as Group Chief Marketing Officer.UltraViolet Cyber has named Andrew Park Chief Information Security Officer.More People On The MoveExpert Insights Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while k