Suspected Iran-linked attack knocked UK power plant offline for days
News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks.
According to sources of UK news outlet The Telegraph, the power plant was offline for four days in July 2026, around the same time when 30+ community water utilities in the US were hit in a coordinated cyberattack
Those attacks happened following a warning about Iranian cyber activity against US energy, water, and government networks.
Limited impact
According to the publication, the incident was reported to the National Cyber Security Centre (NCSC), but it didn’t have a noticeable effect on UK’s power supply.
Michael Shanks, the UK Minister of State in the Department for Energy Security and Net Zero, said that the cyber incident affected a “small-scale energy generator”, but did not name the facility.
“After the incident, we briefed energy CEOs and shared further advice with companies on the steps they should take to stay secure,” he added.
“We work continually with industry, regulators and the National Cyber Security Centre to assess threats and strengthen protections. This follows increased engagement in recent months including the Energy Resilience and Security Taskforce which I chair and which key players from across industry actively participate.”
What the experts are saying
James Griffiths, founder of UtopianKnight Consultancy and a former adviser at UK’s intelligence and security agency GCHQ, says the incident is a wake-up call for the rest of the critical national infrastructure community.
“Although nothing has been released about how this happened, what is interesting is that it took four days for the power plant to come back online,” he noted.
“Now, depending on the scale of the attack against the plant, this could be deemed as quite a quick recovery to operations. But the more serious question is how interconnected was that power plant to the rest of the national grid network and could the attackers have been able to move to other areas? If made public, it will be interesting to see what lessons are identified so we can all really understand how frail some of the smaller power plants are.”
Dan Bird, EMEA Field CTO at Horizon3.ai, says the UK should consider this attack as a clear message that critical infrastructure and the supply chains that feed it are now fair game.
“Cyber gives adversaries a way to create strategic impact below the threshold of war and provable attribution remains a challenge,” he noted.
“The next attack may not be limited to a single site. It could hit multiple smaller operators at once, or a more significant part of the energy system. That is why UK organisations in critical supply chains must not assume they are too small or too peripheral to be targeted.”
The priority now is to find the exploitable gaps before an adversary does.
“Vulnerabilities will always exist, but organisations need to continuously test whether those weaknesses create real attack paths, then close them before they can threaten operations, supply or national resilience,” he added.
Tim Williams, CEO at London-based cybersecurity and software company Quod Orbis, expects critical national infrastructure such as electricity, power and water to be targets for more attacks.
“Resilience will really depend on knowing, in real time, whether the controls designed to protect critical operations are actually working, and having clear accountability when they are not,” he told Help Net Security.
“Continuous assurance needs to become part of how organisations manage operational resilience, particularly as state-linked actors increasingly look for ways to exploit the digital systems underpinning essential services.”
The wider threat landscape
Last year, the UK government introduced a new legislation aimed at improving the country’s resilience against cyber threats by forcing public services and digital services providers to strengthen their digital defenses.
The Cyber Security and Resilience Bill is currently moving through Parliament and is expected to pass into law in late 2026, though will take a few years to see the effect.
Iran might have increased the rate at which it mounts cyber attacks on countries that it considers to be its enemies (or allies of its enemies), but is not the only country whose cyber offensive capabilities have been aimed at disrupting the delivery of energy and heat.
Ukraine’s power grid has been repeatedly targeted by Russia-backed APT group Sandworm since the start of the war.
Late last year, the Polish government revealed suspected Sandworm attacks aimed at crippling Poland’s energy infrastructure.
In July 2026, the EU and UK imposed sanctions against Russia’s cyber operators – both individuals and companies – over efforts to destabilize Europe by targeting public services and critical infrastructure in many European countries.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
