HomeSecurityIranian hackers shut down British power plant for 4 days

Iranian hackers shut down British power plant for 4 days

Iranian hackers managed to shut down a British power plant for four days in July 2026. The news was first reported on August 22, 2026 by The Telegraph, followed by reports from the BBC, the Guardian , and the Financial Times. The delay in reporting the incident for several weeks suggests that the authorities wanted to handle the incident discreetly, avoiding public panic.

Iranian hackers cyberattack British power plant OT ICS

The facility affected was reportedly a small-scale generation unit and posed no threat to the wider national electricity grid. However, the significance of the incident lies not in the size of the facility, but in the fact that a cyberattack managed to cause four days of actual operational disruption to the UK’s energy infrastructure.

It is noteworthy that there has been almost no official announcement from relevant bodies, such as the NCSC (National Cyber ​​Security Centre). Some media outlets have reported that the Western cybersecurity world is on alert for attacks from Iran due to its conflict with the US and Israel. However, so far the activity has been limited. This assessment, however, is misleading: since the start of the conflict, Iranian hackers have attacked multiple targets in the US, Israel, the Gulf Cooperation Council (GCC) and Europe.

See also: Iranian Hackers Target US Critical Infrastructure with PLC Attacks

Iranian hackers and the expansion into British energy infrastructure

Muhammad Yahya Patel, cybersecurity consultant for the EMEA at Huntress, poses a critical question: “The significance lies not in the size of the facility, but in the fact that a cyberattack turned into four days of actual operational disruption. This raises an important question: why did the recovery take four days, and are smaller operators adequately prepared to mitigate and recover from such incidents?” This question touches on one of the weakest links in critical infrastructure security: small and medium-sized facilities that often lack the resources or expertise to deal with sophisticated cyberattacks.

Phil Tonkin, Field CTO at Dragos, points out that the loss of a single facility is not in itself a major security risk. However, he stresses that “these are often repeated attacks that could be deployed at scale.” This means that if Iranian hackers have developed a reliable method of infiltrating British energy facilities, the same tactic could be applied to multiple targets simultaneously, with much more serious consequences for the national grid.

Rafael Narezzi, CEO of Centrii, shares a similar concern: “What worries me about this incident is not necessarily the size of the plant that was affected, but how many others there might be out there. This particular incident may not have had consequences for the wider grid, but the next one could be different.” The expert adds that the UK has thousands of distributed energy assets that are increasingly contributing to the operation of the energy system. “Individually, many may seem insignificant. Collectively, their resilience matters enormously.”

Iranian hackers shut down British power plant for 4 days

Technical Details: How Iranian Hackers Invade OT/ICS Systems

While no specific exploit, malware , or CVE for this incident, experts are identifying the most likely attack vectors. In industrial power generation environments, the most common vulnerabilities include: exposed PLC and HMI to the internet, insecure remote access services, weak or default credentials, and exposed industrial protocols such as Modbus, DNP3, EtherNet/IP, S7 , and BACnet.

See also: Hackers exploit critical RCE vulnerability in Microsoft Entra ID

Graeme Stewart, head of public sector at Check Point, warns emphatically: “This marks a serious escalation in the conflict with Iran, as a cyber threat linked to a hostile state has reached the UK’s energy infrastructure and caused a physical outage lasting four days. This should be of concern to any organisation responsible for the operation of this country. The fact that it was a relatively small plant does not eliminate the threat. The far more serious point is what the attackers appear to have demonstrated: the ability to penetrate the UK’s energy infrastructure and stop it from operating.”

Iranian hackers - SecNews.gr

Iranian hackers: History and broader threat context

Since the start of the conflict with the US and Israel, Iranian hackers have targeted critical infrastructure of the US and its allies. A series of cyberattacks on US water infrastructure affected 12 states around the same time period, confirming that OT/ICS remains active and geographically widespread.

The UK should not be surprised to find itself in the crosshairs. The biggest surprise, in fact, is that this appears to be the only known successful Iranian cyberattack against British infrastructure to date. According to SecurityWeek, the expansion of Iranian cyber operations into the UK should not be underestimated, and cybersecurity experts are not minimizing its significance.

See also: CVE-2026-59310: Chinese hackers exploit VMware vCenter vulnerability

For operators of industrial and energy facilities, the main lesson from this incident is that small or lesser-known facilities can be of strategic importance , and “limited” does not mean “low risk.” Early cooperation with national cybersecurity authorities and specialized incident response teams remains critical for rapid recovery and damage limitation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS