Security

Iran-Linked Hackers Shut Down a UK Power Plant for Four Days, Telegraph Reports

A suspected Iranian cyberattack took a small UK power station offline for four days in July, the first such incident in Britain, while the FBI warned that attackers are now using AI-generated exploit scripts against Siemens S7 PLCs.

T
By Tom Evans Robotics Correspondent
August 25, 2026 / 6 min read

A suspected Iranian-linked cyberattack took a small UK power station offline for four days in July, the first disruptive Iranian cyberattack on British energy infrastructure, the Telegraph reported on August 24 and the Financial Times confirmed. A UK government spokesperson told The Register that the security incident affected a 'small-scale energy generator' and that there was 'no risk to the wider energy system,' but Energy Minister Michael Shanks briefed energy CEOs and issued updated security guidance to companies after the incident.

How It Compares to the US Attacks

The British incident came in the same month that suspected Iranian cyber operatives disrupted more than 30 water facilities in Minnesota, with similar intrusions subsequently reported across at least 11 other US states. CISA and private-sector threat analysts have told The Register that Iran is 'almost certainly' behind the breaches, which appear to be a direct response to the ongoing Middle East conflict. CISA has documented that Iranian-linked actors are using relatively simple techniques — scanning for exposed devices and exploiting default credentials — rather than zero-day exploits, more akin to looking for unlocked doors than high-tech hacking. The U.K.'s National Cyber Security Centre disclosed in June that it had managed more than 200 cyberattacks against UK critical infrastructure in the past year, with roughly 75% linked to hostile states including Russia, China, and Iran.

The AI-Assisted Angle

Last week, the FBI and four other federal agencies warned that attackers are now using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities. 'This is not a theoretical risk — it is an active threat,' the agencies said in a joint advisory. Cynthia Kaiser, senior vice president at the Halcyon Ransomware Research Center and a former FBI cyber analyst, told The Register that the activity appears to be a continuation of the same suite of intrusions targeting operational technology across the U.S. and U.K.

Strategic Implications

The British and American intrusions are widely viewed as proof-of-concept attempts to map how to navigate the systems of more vulnerable critical-infrastructure targets before attempting more sensitive, high-value facilities. The NCSC has warned about Iranian-linked cyber activity for years, including condemning Iran for a 2022 attack on Albanian government services, but warnings intensified sharply after the U.S.-Israel war against Iran and the killing of Supreme Leader Ayatollah Ali Khamenei earlier this year. The British incident is the first time the warnings have crystallized into a publicly confirmed disruptive attack on UK energy infrastructure.

What to Watch Through Year-End

Three checkpoints follow. The NCSC's annual review, expected in late September, will quantify how many of the 200 incidents already disclosed were linked to Iran specifically and will likely upgrade the threat level for the energy sector. Japan's government has separately published draft guidelines this week recommending 150 cybersecurity measures for critical infrastructure operators, including adoption of post-quantum cryptography by 2035, which is likely to set a precedent for U.S. and U.K. regulators. And the next round of joint advisories from CISA, NCSC, and their partners, expected this autumn, will determine whether the AI-assisted PLC exploitation becomes a sustained campaign or remains a narrow set of high-profile incidents.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.