Iranian hackers shut down âsmallâ UK power station for 4 days
Hackers linked to Iranâs Islamic Revolutionary Guard Corps (IRGC) are understood to have successfully shut down a âsmallâ UK power station.
The attack was first reported in The Daily Telegraph newspaper. However, government bodies responsible for the energy network say it has no impact on the wider electricity system.
The power plant was shut down for four days while staff tried to bring it back online, according to the newspaper.
Officials from the Department for Energy Security and Net Zero (DESNZ) are understood to have briefed energy CEOs and directly wrote to companies with advice, direction and next steps.
A government spokesperson said: âThe UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.
âThis [newspaper] story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.â
A National Energy System Operator (Neso) spokesperson said: âGreat Britainâs energy system is highly resilient, and Neso continuously reviews and manages threats to its security, including cyber risks.
âThe incident reported had no impact on the wider electricity system. We work closely with DESNZ, NCSC, Ofgem and industry to maintain security and resilience.
âWe do not comment on specific security measures.â
National Preparedness Commission chair Lord Harris told NCE: âThese reports indicate the cyber-vulnerability of key parts of our national infrastructure.
âWe are not alone in this, reports suggest that dozens of water plants in multiple US states have been subjected to concerted cyber attacks in recent months.
âThis â following on from the cyber-attacks on M&S, the Co-op and Jaguar Land Rover that inflicted huge financial costs [not just] on the businesses concerned but all their supply chains and customers â highlights why as a nation we have got to take cyber resilience much more seriously.â
Cybersecurity firms e2e-assure, Huntress and Check Point also commented on the incident.
e2e-assure CEO Rob Demain told NCE: âI want to caveat that we still donât know how this attack was carried out. The plant hasnât been named, no technical detail has been released, and the NCSC hasnât commented, so anyone claiming AI was involved in this specific incident is speculating, and Iâd include myself in that.
âWhat I can say with confidence is that AI is impacting the direction of travel. AI is lowering the barrier to entry for attackers; it helps them find weaknesses faster, get to grips with unfamiliar industrial and control systems more quickly, and craft and repeat attacks at a scale that used to need a skilled team.
âThis is particularly significant for CNI (critical national infrastructure) because so much of it runs on similar equipment, remote-access arrangements, and suppliers.
He added: âA flaw that once had to be found by hand, one site at a time, can increasingly be hunted across hundreds of near-identical assets at once. The economics of attacking the estate weâve built are shifting in the attackerâs favour.
âThis is happening now. Attacks on critical infrastructure are already rising, with the NCSC now handling around four nationally significant incidents a week, a large share of which touch national infrastructure, and AI is helping the attackers scale those attacks.
âFor those who design, build, and operate this infrastructure, the takeaway is that they need to assume these systems will be probed, and so to build and run them so abnormal behaviour is visible quickly, treating security as part of the engineering, not something added at the end. Defenders get the same speed from AI that attackers do, but only if we use it.â
Huntress vCISO (virtual chief information security officer) and cybersecurity advisor for EMEA (Europe, Middle East and Africa) Muhammad Yahya Patel said: âThe significance isnât the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.
âThat raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?
âThere is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.
âCritical infrastructure security cannot stop with the organisations considered large enough to be critical. Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem.â
Check Point head of public sector Graeme Stewart said: âThis marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days.
âThat should concern every organisation responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat.
âThe far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.â
He added: âWe have to ask: âWhat happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on?ââ
The government confirmed that GCHQâs (Government Communications Headquarters) National Cyber Security Agency (NCSC) responds to serious cyber incidents impacting UK organisations, providing support to impacted organisations, and coordinating across government.
DESNZ added that plans are in place to ensure the resilience of UK energy supply in the unlikely event of significant disruption, regardless of the cause.
The governmentâs National Risk Register 2026 included a risk profile covering âcyber attack: electricity infrastructureâ.
It said: âThe average impact score for risks grouped under the âcyber attacks on infrastructureâ category is 3 (moderate) and the average likelihood score is 4 (5â25%).
A moderate impact is quantified as 41-200 fatalities, and/or 81-400 casualties, and/or hundreds of millions of pounds in economic costs.
The Network and Information Systems Regulations (2018) already set cyber resilience requirements for the most critical operators across the energy system and the regulations are being updated by the Cyber Security and Resilience Bill, which is currently in Parliament.
The Energy Sector Cyber Security Strategy explains the governmentâs plans to further protect the energy system and its consumers, and how the government is working with industry to mitigate cyber risks.
DESNZ is working on an Energy Resilience Strategy for publication later in 2026, which sets out a plan for ensuring the energy system stays resilient today and throughout the energy transition to a wide range of risks, including climate change, technology advancements and geopolitical developments.
Earlier in August, UK and allied spy agencies said they had exposed Russian state-supported actors which had been targeting Western government and commercial organisations, including in the energy sector.
Have your say
or a new account to join the discussion.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.