Mastodon Skip to content Breaking US C-17 lands in Moscow with CIA chief Ratcliffe aboardUS C-17 lands in Moscow with CIA chief Ratcliffe aboardUS C-17 lands in Moscow with CIA chief Ratcliffe aboardUS C-17 lands in Moscow with CIA chief Ratcliffe aboardUS C-17 lands in Moscow with CIA chief Ratcliffe aboard
pulseofnations. Real News. Global Impact.
Subscribe
live markets
S&P 5007,677.28▲ 3.58%NASDAQ26,151.30▲ 4.71%DOW53,577.40▲ 3.14%GOLD4,716.00▲ 15.94%WTI80.40▼ 9.98%BRENT85.31▼ 11.85%EUR/USD1.1675▲ 2.62%USD/JPY158.95▼ 2.98%DXY98.91▼ 2.53%BTC$78,921▼ 2.45%ETH$2,462▼ 2.22%SOL$97.16▼ 4.70%TOTAL CRYPTO$2.67T▼ 3.80%

Iran-Linked Hackers Shut Down UK Power Plant for Four Days

Suspected Iran-linked hackers forced a small UK peaker plant offline for four days, prompting government briefings on energy sector cyber risk.

Partner Surfshark VPN

Suspected Iran-linked hackers forced a small UK power generator offline for four days in a cyberattack that has prompted the British government to brief energy industry executives about the growing threat to operational technology systems.

The attack, first publicly reported on Aug. 22 by the Telegraph, targeted a small gas-fired peaker plant with a capacity of about 15 megawatts, connected to a local electricity distribution network. Neither the government nor the National Cyber Security Centre (NCSC) would identify the facility or its owner, citing security concerns. The Department for Energy Security and Net Zero (DESNZ) confirmed that at no point was there a risk to the UK energy system, and no power cuts were reported.

The affected plant was one of roughly 300 similar peaker facilities across the UK, which collectively provide between 4GW and 7GW of short-term capacity during peak demand. These smaller generators are typically operated remotely using programmable logic controllers (PLCs) – the same class of devices that cybersecurity researchers have flagged as increasingly vulnerable to state-sponsored intrusions.

Government Briefs Energy Sector After Incident

The DESNZ contacted power companies following the attack to advise them about cyber risks, while ministers were briefed on the situation. The incident was reported to the NCSC, part of GCHQ, but technical details about the access method or specific vulnerabilities exploited remain undisclosed. A former security official described the attack as a “clear warning shot from the Iranian state,” noting that Iran had already disrupted global oil supplies and was now threatening critical national infrastructure in the UK.

Lord Walney, the government’s former adviser on political violence, said the incident “underlines that Iran is conducting a hybrid war against the UK with significant impact on British citizens” and called for ministers to “urgently step up a co-ordinated strategy that increases resilience against Iranian activity at all levels.”

Part of Wider Iranian OT Campaign

The UK incident fits a broader pattern of suspected Iranian targeting of industrial control systems across Western nations. In early August, at least seven US states reported intrusions into water treatment systems, with cybersecurity researchers linking those attacks to the group known as CyberAv3ngers. Days later, the FBI and CISA issued a joint advisory warning that attackers were using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, and energy facilities.

That advisory, which did not formally attribute the campaign to Iran, came from a joint effort by the NSA, CISA, FBI, Department of Energy, and EPA. “This is not a theoretical risk – it is an active threat,” the agencies warned. The attackers reportedly use open-source industrial automation libraries combined with AI coding assistants to create custom tools that mimic operational technology monitoring software.

Cynthia Kaiser, Halcyon Ransomware Research Center SVP, told The Register that the UK attack “appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs.” She noted that Iranian-affiliated adversaries are actively targeting a wide swath of operational technology because PLCs underpin essential health, safety, and critical infrastructure across society.

Scale of UK Exposure Raises Concerns

While the UK government emphasized that the affected plant was not critical to the national grid, cybersecurity experts warned that the attack demonstrated Iran’s willingness and ability to reach British infrastructure. NCSC chief executive Richard Horne said this month that hostile states were linked to approximately three-quarters of cyber incidents affecting the UK’s critical systems over the previous year, with Russia, China, and Iran identified as the primary threats.

The incident also highlighted the vulnerability of smaller, less-protected energy facilities that operate with limited cybersecurity budgets and may lack dedicated OT security teams. Unlike large power stations with robust network segmentation, smaller peaker plants often rely on remote access configurations that can expose PLCs to the internet if improperly secured.

The UK is currently updating its cyber security regulations and developing a new energy resilience strategy expected later this year. The attack adds urgency to those efforts as state-linked cyber operations against critical infrastructure continue to escalate worldwide.

SourcesThe Telegraph; BBC News; The Guardian; CISA advisory AA26-231a; The Register
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch 274 Zimbra Servers Hacked as CISA Patch Deadline Expires Read →