Aug 24
/
Latest News
UK Probes Suspected Iranian Cyberattack After Power Plant Forced Offline for Four Days
A British power plant was forced offline for four days in July following a suspected Iranian cyberattack, raising fresh concerns about the resilience of the UK’s critical infrastructure. The incident occurred around the same time more than 30 U.S. community water utilities were hit in a coordinated intrusion.
According to reporting by The Telegraph, the shutdown was disclosed to the National Cyber Security Centre (NCSC), though officials said the disruption did not affect the country’s overall power supply. Michael Shanks, Minister of State in the Department for Energy Security and Net Zero, described the affected facility as a “small-scale energy generator” but did not name the site.
Shanks said the government briefed energy-sector CEOs after the incident and issued additional guidance on strengthening cyber defenses. “We work continually with industry, regulators and the National Cyber Security Centre to assess threats and strengthen protections,” he noted, pointing to recent efforts through the Energy Resilience and Security Taskforce.
Security experts say the episode should serve as a warning for operators across the UK’s critical national infrastructure. James Griffiths, founder of UtopianKnight Consultancy and a former adviser at GCHQ, said the four‑day outage raises questions about the plant’s connectivity to the wider grid and whether attackers could have moved laterally. “If made public, it will be interesting to see what lessons are identified so we can understand how frail some of the smaller power plants are,” he said.
Dan Bird, EMEA Field CTO at Horizon3.ai, said the attack should be viewed as a clear signal that critical infrastructure and its supply chains are now “fair game” for state-linked adversaries. “The next attack may not be limited to a single site,” he warned. “It could hit multiple smaller operators at once, or a more significant part of the energy system.”
Bird emphasized that organizations must identify exploitable gaps before attackers do. “Vulnerabilities will always exist, but organisations need to continuously test whether those weaknesses create real attack paths, then close them before they can threaten operations, supply or national resilience.”
Tim Williams, CEO of London-based cybersecurity firm Quod Orbis, said critical national infrastructure—including electricity, power, and water—should expect more targeted attacks. “Resilience will depend on knowing, in real time, whether the controls designed to protect critical operations are actually working,” he said. “Continuous assurance needs to become part of how organisations manage operational resilience.”
The incident comes amid a broader uptick in cyber activity targeting energy systems worldwide. The UK government is advancing the Cyber Security and Resilience Bill, aimed at strengthening digital defenses across public and digital service providers. The legislation is expected to pass in late 2026, though its full impact will take years to materialize.
Iran-linked groups have increasingly targeted industrial systems in recent years. U.S. agencies warned earlier this year that Iranian-affiliated actors were exploiting internet-connected PLCs from Rockwell Automation, Schneider Electric, and Siemens. Days later, a coordinated cyberattack disrupted operational technology at more than 30 water utilities in Minnesota, with researchers attributing the activity to the Iran-linked CyberAv3ngers group.
Russia-backed Sandworm has also repeatedly targeted Ukraine’s power grid since the start of the war, and Polish officials disclosed suspected Sandworm activity aimed at crippling Poland’s energy infrastructure late last year. In July 2026, the EU and UK imposed sanctions on Russian cyber operators for efforts to destabilize European critical infrastructure.
According to reporting by The Telegraph, the shutdown was disclosed to the National Cyber Security Centre (NCSC), though officials said the disruption did not affect the country’s overall power supply. Michael Shanks, Minister of State in the Department for Energy Security and Net Zero, described the affected facility as a “small-scale energy generator” but did not name the site.
Shanks said the government briefed energy-sector CEOs after the incident and issued additional guidance on strengthening cyber defenses. “We work continually with industry, regulators and the National Cyber Security Centre to assess threats and strengthen protections,” he noted, pointing to recent efforts through the Energy Resilience and Security Taskforce.
Security experts say the episode should serve as a warning for operators across the UK’s critical national infrastructure. James Griffiths, founder of UtopianKnight Consultancy and a former adviser at GCHQ, said the four‑day outage raises questions about the plant’s connectivity to the wider grid and whether attackers could have moved laterally. “If made public, it will be interesting to see what lessons are identified so we can understand how frail some of the smaller power plants are,” he said.
Dan Bird, EMEA Field CTO at Horizon3.ai, said the attack should be viewed as a clear signal that critical infrastructure and its supply chains are now “fair game” for state-linked adversaries. “The next attack may not be limited to a single site,” he warned. “It could hit multiple smaller operators at once, or a more significant part of the energy system.”
Bird emphasized that organizations must identify exploitable gaps before attackers do. “Vulnerabilities will always exist, but organisations need to continuously test whether those weaknesses create real attack paths, then close them before they can threaten operations, supply or national resilience.”
Tim Williams, CEO of London-based cybersecurity firm Quod Orbis, said critical national infrastructure—including electricity, power, and water—should expect more targeted attacks. “Resilience will depend on knowing, in real time, whether the controls designed to protect critical operations are actually working,” he said. “Continuous assurance needs to become part of how organisations manage operational resilience.”
The incident comes amid a broader uptick in cyber activity targeting energy systems worldwide. The UK government is advancing the Cyber Security and Resilience Bill, aimed at strengthening digital defenses across public and digital service providers. The legislation is expected to pass in late 2026, though its full impact will take years to materialize.
Iran-linked groups have increasingly targeted industrial systems in recent years. U.S. agencies warned earlier this year that Iranian-affiliated actors were exploiting internet-connected PLCs from Rockwell Automation, Schneider Electric, and Siemens. Days later, a coordinated cyberattack disrupted operational technology at more than 30 water utilities in Minnesota, with researchers attributing the activity to the Iran-linked CyberAv3ngers group.
Russia-backed Sandworm has also repeatedly targeted Ukraine’s power grid since the start of the war, and Polish officials disclosed suspected Sandworm activity aimed at crippling Poland’s energy infrastructure late last year. In July 2026, the EU and UK imposed sanctions on Russian cyber operators for efforts to destabilize European critical infrastructure.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.