A small-scale power plant in the United Kingdom was shut down for four days in July following a cyberattack attributed to hackers linked to Iran, according to reports published on Sunday. British officials have not identified the facility but confirmed it posed no risk to the national energy grid.
Government confirms incident but declines attribution
A spokesperson for the U.K. government stated that the incident involved a small-scale energy generator and emphasized that the wider energy system remained unaffected. "This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system," the spokesperson told CNBC. "The U.K. has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards."
The Department of Energy Security and Net Zero reported that it briefed energy company executives and issued guidance to businesses following the incident. The department also noted that it is updating cybersecurity regulations in response to the attack.
Attack occurred amid broader cyber campaign
The reported shutdown took place around the same time U.S. authorities warned of cyber threats targeting water facilities across multiple states. The Cybersecurity and Infrastructure Security Agency, FBI, Environmental Protection Agency, and other agencies attributed these activities to Iran. U.S. President Donald Trump stated in late July that he did not believe Iran was responsible for the attacks on American infrastructure.
Joe Slowik, director of threat research for Dataminr, told The Washington Post that similar attacks on water and energy systems in the United States have occurred since the beginning of the conflict with Iran. "It is not a secret that these things have been taking place since the spring," Slowik said. "There have been disruptions."
Context of cyber tensions
Cybersecurity experts have noted an increase in state-sponsored cyber activities targeting critical infrastructure in recent months. Earlier this year, Dr. Richard Horne, head of the U.K.’s National Cyber Security Centre (NCSC), warned that most nationally significant cyberattacks on Britain were carried out by hostile states, including China.
The NCSC, part of GCHQ, is responsible for responding to serious cyber incidents affecting U.K. organizations. While the specific facility targeted in the July incident has not been named, reports describe it as a small-scale generator with no impact on national power supply.
International responses and ongoing investigations
The U.K. government has not publicly attributed the attack to any specific actor. In the United States, the Department of Justice charged 17 Iranians in August with conducting a "massive cyber theft campaign" on behalf of the Islamic Revolutionary Guard Corps and other Iranian entities. Iran has also been the target of cyberattacks, including a June breach of its largest cryptocurrency exchange, Nobitex, which resulted in losses exceeding $90 million.
The reported incident in the U.K. follows broader concerns about the vulnerability of critical infrastructure to cyber threats. British officials have stressed the resilience of the national energy system while acknowledging the need for continued vigilance and regulatory updates.