Skip to main content
Advertisement

Iran-linked hackers shut down UK power plant in apparent retaliation escalation

Iran-linked hackers have shut down a UK power plant in an apparent escalation following Britain's decision to allow US defensive operations from British bases. The four-day outage affected a small-scale generator with no impact on the wider energy system.

By The UK Pulse Editorial Team··4 min read·How we work
Richard Horne, NCSC CEO, speaks with a headset microphone against a purple backdrop

Hackers with connections to Iran have been identified as responsible for a cyber-attack that forced a British power plant offline, marking what officials believe to be the first successful breach of its kind against UK energy infrastructure by Tehran-affiliated actors.

The incident targeted a small-scale energy generator and resulted in a four-day shutdown last month. The UK government confirmed that at no stage did the attack pose a threat to the broader energy network, which maintains robust defences against such intrusions.

The timing of the attack appears significant given recent geopolitical developments. The UK announced last month that it had authorised the United States to conduct what it describes as "defensive" operations against Iran from British military bases. Iran's Islamic Revolutionary Guard Corps (IRGC) responded by declaring that

any base used for aggression against Iranian territory constitutes a legitimate target for our forces
.

A spokesperson for the Department for Energy Security and Net Zero stated:

This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.

How widespread is the threat to UK energy systems?

The National Cyber Security Centre (NCSC), which oversees defences against attacks on critical infrastructure, has not received any reported outages from regulated power station operators, suggesting the incident remained isolated. However, the broader picture of cyber threats to British infrastructure is concerning. According to the NCSC, more than 200 cyber incidents affecting UK critical national infrastructure were handled in the year to June 2026, with approximately 75% linked to state actors.

Advertisement

Hostile nations including Russia, China and Iran have intensified their targeting of systems underpinning the UK's essential services. The NCSC has previously warned that Iran-based threat actors remain aggressive and continue to target industrial control systems, which explains why disruption to energy infrastructure carries particular significance.

What is the context of UK-US military cooperation with Iran?

The UK has permitted the United States to launch defensive operations from British bases hosting American aircraft since the beginning of the US military campaign against Iran. However, the government has declined to participate in offensive operations. This policy framework has remained unchanged under the current Prime Minister, Andy Burnham, who was informed last week that the agreement with the US would be extended.

The UK previously stated it stands ready to defend itself after Iran named British bases used by the US as legitimate targets, a declaration made as the US carried out its 13th night of strikes on Iranian positions.

What is Iran's track record in cyber-attacks?

Iran has faced accusations for years of conducting cyber-attacks against numerous countries. In 2022, the nation was linked to several breaches of Israeli government websites. The US government security agencies issued a warning earlier this year regarding cyber-attacks on critical infrastructure by hackers connected to the IRGC.

The US has specifically attributed a campaign known as "CyberAv3ngers" to an Iran-affiliated group, alleging that this operation in 2023 compromised at least 75 devices across multiple infrastructure sectors within American territory.

What steps are being taken to prevent future attacks?

Following the incident, UK officials have briefed energy company chief executives and distributed guidance to the sector, indicating that coordinated mitigation measures are underway to strengthen defences against similar intrusions. These actions underscore the government's recognition that energy infrastructure remains a priority target for hostile state actors.

Key Facts

  • The cyber-attack shut down a small-scale energy generator for four days last month and is believed to be the first successful breach of a British energy facility by Iran-linked hackers
  • The UK government confirmed no risk to the wider energy system, which maintains robust resilience against such attacks
  • Approximately 75% of the 200+ cyber incidents affecting UK critical infrastructure in the past year were linked to state actors, according to the NCSC
  • The attack follows the UK's decision to allow the US to conduct defensive operations against Iran from British bases
  • Energy sector leaders have been briefed and issued guidance as part of ongoing mitigation efforts

This article was sourced from theguardian

Advertisement

Related News