A UK power plant reportedly went dark for four days in July after a cyberattack linked to Iranian hackers, but the story only surfaced this week, and the UK government still hasn’t confirmed or denied the incident or the attribution
The government said that at no point was there a risk to the UK’s energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of cyber attacks.
The Telegraph reported that the attack, which took place last month, was carried out by hackers affiliated to the Iranian regime.
For security reasons, neither the government nor the National Cyber Security Centre, which deals with attacks on critical infrastructure, would give further details of the site affected. However this was not an attack on an essential service such as a large power station.
Josh Picolet, VP of Detection & Analysis, Team Cymru
“State-linked activity against critical infrastructure tends to follow patterns that outlast any single incident, and the four-day recovery window here is the detail worth studying closely. That length of disruption usually means the attacker had dwell time inside the environment before detection, which points to a gap in visibility rather than a one-off failure.
It’s worth noting the UK government has neither confirmed nor denied the incident or the attribution to Iran-linked actors, so defenders should treat the public reporting with appropriate caution while still taking the operational lesson seriously. Regardless of formal attribution, the pattern is consistent with what we’ve tracked from Iran-affiliated groups against critical infrastructure across the US, Israel, the Gulf, and now Europe this year. Smaller operators in particular need intelligence that surfaces staging and pre-positioning activity, not just indicators tied to a confirmed actor, because the next facility targeted may not get four days of warning before impact.”
Justin Beals, CEO & Founder, Strike Graph
“Four days of downtime at a critical infrastructure facility is not a technical failure. It’s a governance failure. Somewhere in that plant’s compliance program, a control existed on paper that didn’t hold up in practice, and nobody caught the gap until an adversary found it first.
This is the same story we keep seeing across sectors. Organizations treat security posture as something you attest to once a year, not something you verify continuously. A point-in-time audit tells you a plant was secure on the day someone checked. It tells you nothing about the day the attacker showed up.The UK has thousands of smaller energy assets like this one, and most of them are operating on the same annual-attestation model. If this attack is repeatable, and there’s no reason to think it isn’t, the operators still relying on periodic reviews instead of continuous monitoring are the ones who will be explaining a multi-day outage to their regulator next.”
Expect more state sponsored actors to do hacks like this. Because there’s likely more of this out there that is under reported.
UPDATE: John Strand, Owner, Black Hills Information Security, Inc. Had This To Say:
“This particular breach scares me, not necessarily because it happened in the United Kingdom, but because of how much further behind the United States power grid is compared to Europe. Modernization of the U.S. power grid has been painfully slow for a number of reasons, including legislative capture and the basic economics of how utilities make money. They make money from generating and selling power. They don’t necessarily make money from updating aging infrastructure.
“Then there’s the interconnected nature of the U.S. power grid, with Texas being the notable exception. A relatively small problem at a substation can create ripple effects across multiple areas of the grid. That’s what makes this such a serious wake-up call. When you combine that interconnectedness with the incredibly slow pace of infrastructure modernization, especially across the power grid, I’m very concerned. I think an attack like this could potentially have a far greater impact in the United States than what we’re seeing in Europe.”
Denis Calderone, CTO, Suzu Labs:
“What has our attention here is not the size of the generator. A savvy attacker isn’t choosing targets based on grid capacity. They’re probing for the weakest point in the armor, and a facility small enough to fall below mandatory cyber reporting thresholds is exactly the kind of target that’s likely under-defended and overlooked.
“Two weeks ago in Poland, a compromised wind farm became a direct bridge into a completely separate heating plant’s SCADA system through a shared cellular network. Different threat actor, different country, same playbook: find the overlooked facility, use it as a stepping stone. We’ve been tracking Iran-linked operations against Western critical infrastructure since April, and the pattern keeps escalating. PLCs targeted for operational disruption. Gas station fuel monitoring systems. Water systems across 12 US states in a single month. Five agencies flagged AI-generated tools targeting Siemens PLCs four days ago. And now a UK power facility goes dark for four days.
“The victim became the victim because of poor hygiene. The advice here is the same as it ever was, because the exposure hasn’t changed. Take controllers off the internet. Change default credentials. Inventory every communication path, especially the integrator-installed remote access links and the backup channels that never made it onto a network diagram. But critical infrastructure operators need to be proactively hunting for these weaknesses and prioritizing remediation before an adversary does the discovery for them. The smaller satellite sites are often the ones that fall under the radar during security reviews, so make sure you look at everything. Small and overlooked is exactly what made this target attractive.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
“There is a real and growing threat to critical infrastructure, however the way we talk about these incidents matters.
“If this was genuinely a historic cyber-induced shutdown of a British power generator, then operators need to know what made it possible. Was a PLC directly exposed to the Internet? Was remote access compromised? Did attackers manipulate the physical process, or did operators shut the plant down defensively after an IT compromise? What control would have broken the attack chain?
“Don’t tell me this was historic and then redact the history.
“We can protect the identity of the victim and sensitive operational details while still publishing a sanitized technical account. CERT Polska has shown what responsible disclosure can look like: explain the attack path, identify the class of failure, and give other operators something they can actually use to defend themselves.
“The same caution applies to attribution. “Iran-linked” is not the same thing as proving that the Iranian government directed the attack. We should distinguish what happened to the plant, who conducted the intrusion, and by which nation state it was instructed. Attribution in cyberspace is an analytical conclusion, not something you read off the source IP address.
“The larger problem is that too many cyber incidents and near misses disappear into non-disclosure or tightly held incident reports. One operator learns an expensive lesson while thousands of others are left to learn it again. The point of incident reporting should not simply be counting attacks. It should be making the next attack harder.
“We keep sweeping these incidents and near misses under the rug when we should be dragging them into the light and learning from them.
“If joint cybersecurity advisories can say what went wrong in Minnesota without handing attackers a blueprint, we should be able to tell operators what class of failure took a British peaking plant offline for four days.”
Seemant Sehgal, Founder & CEO, BreachLock:
“OT in power plants and water treatment facilities wasn’t designed with adversarial persistence in mind. The visible coordination across a UK facility and dozens of US water systems in the same window indicates that these environments are being mapped and tested well before the disruptive payload arrives.
“The teams running these facilities need to know which of their OT assets are reachable, how an attacker would move from IT into operational systems, and where their recovery dependencies sit, because it’s already too late to be asking those questions by the time the outage clock starts.”
Related
This entry was posted on August 24, 2026 at 1:33 pm and is filed under Commentary with tags UK. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
UK power plant outage shows why four days of downtime matters more than attribution
A UK power plant reportedly went dark for four days in July after a cyberattack linked to Iranian hackers, but the story only surfaced this week, and the UK government still hasn’t confirmed or denied the incident or the attribution
The government said that at no point was there a risk to the UK’s energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of cyber attacks.
The Telegraph reported that the attack, which took place last month, was carried out by hackers affiliated to the Iranian regime.
For security reasons, neither the government nor the National Cyber Security Centre, which deals with attacks on critical infrastructure, would give further details of the site affected. However this was not an attack on an essential service such as a large power station.
Josh Picolet, VP of Detection & Analysis, Team Cymru
“State-linked activity against critical infrastructure tends to follow patterns that outlast any single incident, and the four-day recovery window here is the detail worth studying closely. That length of disruption usually means the attacker had dwell time inside the environment before detection, which points to a gap in visibility rather than a one-off failure.
It’s worth noting the UK government has neither confirmed nor denied the incident or the attribution to Iran-linked actors, so defenders should treat the public reporting with appropriate caution while still taking the operational lesson seriously. Regardless of formal attribution, the pattern is consistent with what we’ve tracked from Iran-affiliated groups against critical infrastructure across the US, Israel, the Gulf, and now Europe this year. Smaller operators in particular need intelligence that surfaces staging and pre-positioning activity, not just indicators tied to a confirmed actor, because the next facility targeted may not get four days of warning before impact.”
Justin Beals, CEO & Founder, Strike Graph
“Four days of downtime at a critical infrastructure facility is not a technical failure. It’s a governance failure. Somewhere in that plant’s compliance program, a control existed on paper that didn’t hold up in practice, and nobody caught the gap until an adversary found it first.
This is the same story we keep seeing across sectors. Organizations treat security posture as something you attest to once a year, not something you verify continuously. A point-in-time audit tells you a plant was secure on the day someone checked. It tells you nothing about the day the attacker showed up.The UK has thousands of smaller energy assets like this one, and most of them are operating on the same annual-attestation model. If this attack is repeatable, and there’s no reason to think it isn’t, the operators still relying on periodic reviews instead of continuous monitoring are the ones who will be explaining a multi-day outage to their regulator next.”
Expect more state sponsored actors to do hacks like this. Because there’s likely more of this out there that is under reported.
UPDATE: John Strand, Owner, Black Hills Information Security, Inc. Had This To Say:
“This particular breach scares me, not necessarily because it happened in the United Kingdom, but because of how much further behind the United States power grid is compared to Europe. Modernization of the U.S. power grid has been painfully slow for a number of reasons, including legislative capture and the basic economics of how utilities make money. They make money from generating and selling power. They don’t necessarily make money from updating aging infrastructure.
“Then there’s the interconnected nature of the U.S. power grid, with Texas being the notable exception. A relatively small problem at a substation can create ripple effects across multiple areas of the grid. That’s what makes this such a serious wake-up call. When you combine that interconnectedness with the incredibly slow pace of infrastructure modernization, especially across the power grid, I’m very concerned. I think an attack like this could potentially have a far greater impact in the United States than what we’re seeing in Europe.”
Denis Calderone, CTO, Suzu Labs:
“What has our attention here is not the size of the generator. A savvy attacker isn’t choosing targets based on grid capacity. They’re probing for the weakest point in the armor, and a facility small enough to fall below mandatory cyber reporting thresholds is exactly the kind of target that’s likely under-defended and overlooked.
“Two weeks ago in Poland, a compromised wind farm became a direct bridge into a completely separate heating plant’s SCADA system through a shared cellular network. Different threat actor, different country, same playbook: find the overlooked facility, use it as a stepping stone. We’ve been tracking Iran-linked operations against Western critical infrastructure since April, and the pattern keeps escalating. PLCs targeted for operational disruption. Gas station fuel monitoring systems. Water systems across 12 US states in a single month. Five agencies flagged AI-generated tools targeting Siemens PLCs four days ago. And now a UK power facility goes dark for four days.
“The victim became the victim because of poor hygiene. The advice here is the same as it ever was, because the exposure hasn’t changed. Take controllers off the internet. Change default credentials. Inventory every communication path, especially the integrator-installed remote access links and the backup channels that never made it onto a network diagram. But critical infrastructure operators need to be proactively hunting for these weaknesses and prioritizing remediation before an adversary does the discovery for them. The smaller satellite sites are often the ones that fall under the radar during security reviews, so make sure you look at everything. Small and overlooked is exactly what made this target attractive.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
“There is a real and growing threat to critical infrastructure, however the way we talk about these incidents matters.
“If this was genuinely a historic cyber-induced shutdown of a British power generator, then operators need to know what made it possible. Was a PLC directly exposed to the Internet? Was remote access compromised? Did attackers manipulate the physical process, or did operators shut the plant down defensively after an IT compromise? What control would have broken the attack chain?
“Don’t tell me this was historic and then redact the history.
“We can protect the identity of the victim and sensitive operational details while still publishing a sanitized technical account. CERT Polska has shown what responsible disclosure can look like: explain the attack path, identify the class of failure, and give other operators something they can actually use to defend themselves.
“The same caution applies to attribution. “Iran-linked” is not the same thing as proving that the Iranian government directed the attack. We should distinguish what happened to the plant, who conducted the intrusion, and by which nation state it was instructed. Attribution in cyberspace is an analytical conclusion, not something you read off the source IP address.
“The larger problem is that too many cyber incidents and near misses disappear into non-disclosure or tightly held incident reports. One operator learns an expensive lesson while thousands of others are left to learn it again. The point of incident reporting should not simply be counting attacks. It should be making the next attack harder.
“We keep sweeping these incidents and near misses under the rug when we should be dragging them into the light and learning from them.
“If joint cybersecurity advisories can say what went wrong in Minnesota without handing attackers a blueprint, we should be able to tell operators what class of failure took a British peaking plant offline for four days.”
Seemant Sehgal, Founder & CEO, BreachLock:
“OT in power plants and water treatment facilities wasn’t designed with adversarial persistence in mind. The visible coordination across a UK facility and dozens of US water systems in the same window indicates that these environments are being mapped and tested well before the disruptive payload arrives.
“The teams running these facilities need to know which of their OT assets are reachable, how an attacker would move from IT into operational systems, and where their recovery dependencies sit, because it’s already too late to be asking those questions by the time the outage clock starts.”
Share this:
Like this:
Related
This entry was posted on August 24, 2026 at 1:33 pm and is filed under Commentary with tags UK. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.