Iran-Linked Cyber Attack Shuts Down Small UK Power Plant
Hackers linked to the Iranian regime forced a small British power plant to shut down for four days last month, marking what has been described as an unprecedented cyber attack against United Kingdom infrastructure. While the facility remained offline for four days, government officials stated that the incident posed no risk to the national energy supply or broader grid operations.
Scale and Impact of the Incident
The targeted facility is a small-scale gas-fired plant, one of many connected to the national grid that typically operates only for short periods each week. According to the Department for Energy Security and Net Zero (DESNZ), the shutdown did not affect the UK’s wider energy generation. Reports from The Telegraph, indicate the plant remained disabled for four days while staff worked to restore systems. Officials have declined to identify the specific power station, citing security concerns.
The attack is not believed to have caused physical harm to the public or resulted in widespread notice.
Attribution and Regional Context
The breach has been attributed to hackers affiliated with the Iranian regime, specifically those tied to the Islamic Revolutionary Guard Corps (IRGC). This incident follows a series of cyber strikes against water infrastructure in the United States, where hackers targeted facilities across 12 states, resulting in reduced water pressure and boil-water advisories in some communities.

The FBI has attributed the US water infrastructure incidents to malicious cyber actors, with government sources confirming to media outlets that the threat likely originated in Tehran. Since 2023, and particularly following the start of “Operation Epic Fury,” Iran has escalated cyber operations against Western nations. Similar activity has been reported in Germany, Poland, Finland, Belgium, and Albania, though the primary focus of these operations remains in the Middle East.
Government Response and Security Strategy
The UK government has notified the National Cyber Security Centre (NCSC) regarding the breach. In response to the attack, ministers have briefed power company executives and issued new guidance to businesses on strengthening digital defenses. Richard Horne, the NCSC chief executive, reported in June that the agency had managed more than 200 attacks on critical national infrastructure over the previous year.

Current Cabinet Office assessments place the risk of a significant cyber attack on domestic infrastructure at between five and 25 percent. Officials are now working to update cyber security regulations and develop a new energy resilience strategy, which is expected to be finalized later this year.