A small UK power plant experienced a four-day shutdown last month due to a cyberattack reportedly carried out by hackers affiliated with the Iranian regime. The Department for Energy Security and Net Zero (DESNZ) confirmed the incident, stating that it affected a small-scale generator and posed no risk to the UK's broader energy system. Following the attack, DESNZ contacted other power companies to issue advisories regarding the heightened risk of cyberattacks.
The specific power plant was not named due to security concerns, but it was described as a 'peaker' plant, a smaller gas generator used to provide short-term power when needed. This incident marks what is believed to be the first successful cyberattack of its kind against UK energy infrastructure by Iranian-linked actors. The National Cyber Security Centre (NCSC), part of GCHQ, which handles critical infrastructure attacks, declined to provide further details.
The timing of this attack coincides with a series of cyberattacks on US water infrastructure across 12 states in July, which US government sources also linked to Iran. While the UK attack did not aim to harm civilians, its intent was likely to demonstrate the capability of Iran-linked hackers to access and disrupt UK infrastructure. The government emphasized the resilience of the energy system and that the affected site was a very small generator, not near the threshold for mandatory cyber activity notifications.
Experts have previously warned about the UK's preparedness for cyber threats from foreign adversaries. A Cabinet Office risk assessment published recently estimated a 5% to 25% probability of a serious cyberattack on domestic infrastructure, noting that AI is making such attacks faster, cheaper, and more accessible. Iran has reportedly increased its cyberattacks on Western countries following US and Israeli airstrikes in February, with operations reported in Germany, Poland, Finland, Belgium, and Albania, alongside frequent targeting of Israel and other Middle Eastern nations.