Iran hackers shut down UK power plant

Iran-linked hackers shut down UK power generator in landmark attack

According to the Irish Times, SecurityWeek, and Business Today, hackers tied to Iran's Islamic Revolutionary Guard Corps managed to take a British power generation facility offline for four days — described by experts as the most consequential state-linked cyberattack ever to hit UK critical infrastructure. The event occurred in July but was only made public on August 23.

The affected site was a small-scale energy generator, not a major power station. UK authorities emphasized that the national grid remained secure and no customers experienced outages. The Department for Energy Security and Net Zero confirmed the breach but refused to name the facility for security reasons. Energy minister Michael Shanks described the compromised installation as minuscule relative to a typical plant.

The government quietly alerted energy sector executives and circulated updated advisory notices after the incident, which was escalated to the National Cyber Security Centre (NCSC), part of GCHQ.

Analysts believe the intrusion was more about demonstrating capability than causing immediate harm — a proof-of-concept by IRGC-aligned hackers that they could penetrate sensitive domestic networks. No foreign state had previously managed to fully halt a British power generator. The attack coincided with a broader campaign targeting US water infrastructure across a dozen states in the prior month, where Iranian actors focused on programmable logic controllers at water utilities.

Since the US-Iran conflict began in February, the UK has permitted the US to conduct "defensive" operations from British bases housing American aircraft. Iran's military had previously warned that any bases used by the US were legitimate targets. The disclosure has reignited concerns about Western critical infrastructure vulnerability, particularly as the NCSC has flagged increasing targeting of UK essential services by Russia, China, and Iran.

References