Iranian hackers managed to shut down a British power plant for four days in July 2026. The news was first reported on August 22, 2026 by The Telegraph, followed by reports from the BBC, the Guardian , and the Financial Times. The delay in reporting the incident for several weeks suggests that the authorities wanted to handle the incident discreetly, avoiding public panic.

The facility affected was reportedly a small-scale generation unit and posed no threat to the wider national electricity grid. However, the significance of the incident lies not in the size of the facility, but in the fact that a cyberattack managed to cause four days of actual operational disruption to the UK’s energy infrastructure.
It is noteworthy that there has been almost no official announcement from relevant bodies, such as the NCSC (National Cyber Security Centre). Some media outlets have reported that the Western cybersecurity world is on alert for attacks from Iran due to its conflict with the US and Israel. However, so far the activity has been limited. This assessment, however, is misleading: since the start of the conflict, Iranian hackers have attacked multiple targets in the US, Israel, the Gulf Cooperation Council (GCC) and Europe.
See also: Iranian Hackers Target US Critical Infrastructure with PLC Attacks
Iranian hackers and the expansion into British energy infrastructure
Muhammad Yahya Patel, cybersecurity consultant for the EMEA at Huntress, poses a critical question: “The significance lies not in the size of the facility, but in the fact that a cyberattack turned into four days of actual operational disruption. This raises an important question: why did the recovery take four days, and are smaller operators adequately prepared to mitigate and recover from such incidents?” This question touches on one of the weakest links in critical infrastructure security: small and medium-sized facilities that often lack the resources or expertise to deal with sophisticated cyberattacks.
Phil Tonkin, Field CTO at Dragos, points out that the loss of a single facility is not in itself a major security risk. However, he stresses that “these are often repeated attacks that could be deployed at scale.” This means that if Iranian hackers have developed a reliable method of infiltrating British energy facilities, the same tactic could be applied to multiple targets simultaneously, with much more serious consequences for the national grid.
Rafael Narezzi, CEO of Centrii, shares a similar concern: “What worries me about this incident is not necessarily the size of the plant that was affected, but how many others there might be out there. This particular incident may not have had consequences for the wider grid, but the next one could be different.” The expert adds that the UK has thousands of distributed energy assets that are increasingly contributing to the operation of the energy system. “Individually, many may seem insignificant. Collectively, their resilience matters enormously.”

Technical Details: How Iranian Hackers Invade OT/ICS Systems
While no specific exploit, malware , or CVE for this incident, experts are identifying the most likely attack vectors. In industrial power generation environments, the most common vulnerabilities include: exposed PLC and HMI to the internet, insecure remote access services, weak or default credentials, and exposed industrial protocols such as Modbus, DNP3, EtherNet/IP, S7 , and BACnet.
See also: Hackers exploit critical RCE vulnerability in Microsoft Entra ID
Graeme Stewart, head of public sector at Check Point, warns emphatically: “This marks a serious escalation in the conflict with Iran, as a cyber threat linked to a hostile state has reached the UK’s energy infrastructure and caused a physical outage lasting four days. This should be of concern to any organisation responsible for the operation of this country. The fact that it was a relatively small plant does not eliminate the threat. The far more serious point is what the attackers appear to have demonstrated: the ability to penetrate the UK’s energy infrastructure and stop it from operating.”

Iranian hackers: History and broader threat context
Since the start of the conflict with the US and Israel, Iranian hackers have targeted critical infrastructure of the US and its allies. A series of cyberattacks on US water infrastructure affected 12 states around the same time period, confirming that OT/ICS remains active and geographically widespread.
The UK should not be surprised to find itself in the crosshairs. The biggest surprise, in fact, is that this appears to be the only known successful Iranian cyberattack against British infrastructure to date. According to SecurityWeek, the expansion of Iranian cyber operations into the UK should not be underestimated, and cybersecurity experts are not minimizing its significance.
See also: CVE-2026-59310: Chinese hackers exploit VMware vCenter vulnerability
For operators of industrial and energy facilities, the main lesson from this incident is that small or lesser-known facilities can be of strategic importance , and “limited” does not mean “low risk.” Early cooperation with national cybersecurity authorities and specialized incident response teams remains critical for rapid recovery and damage limitation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
