Iranian-Linked Hackers Blamed for U.K. Power Plant Shutdown

Published: August 24, 2026, 11:36 pm

A U.K. power plant was forced offline for four days this past July following a cyberattack that British media outlets are now attributing to hackers with ties to Iran. While the specific facility has not been publicly identified by industrial executives or government officials, reports from the Financial Times and The Telegraph suggest the breach did not disrupt the nation's broader power supply. This incident is believed to mark the first time that Iranian-linked actors have successfully shut down a power facility within the United Kingdom.

The attack occurred during a month characterized by heightened cyber activity, as hackers with similar affiliations are believed to have targeted water systems across a dozen U.S. states, including Minnesota, Georgia, New Jersey, and South Dakota. Those incidents resulted in flooding, pressure loss, and the lockout of system operators. When approached for comment regarding the U.K. facility, the National Cyber Security Centre stated that it would neither confirm nor deny that the hacking event took place.

According to U.S. officials and industry insiders, both the British and American attacks targeted programmable logic controllers, or PLCs. These devices act as the automated "brains" for critical industrial systems globally, regulating functions in manufacturing, water treatment, energy, and beyond. PLCs are also integral to daily public safety, managing traffic light timing, prison security gates, train speeds, and fire suppression systems, as well as providing backup power in hospitals. Market research suggests there are between 12 million and 70 million PLCs currently in use, with many older units predating modern cybersecurity standards.

Security experts note that the methods used to exploit these systems are often surprisingly simple. Rather than deploying complex, high-tech exploits to uncover unknown vulnerabilities, hackers frequently rely on basic techniques like scanning the open internet for exposed devices and exploiting default passwords that were never changed. The Cybersecurity and Infrastructure Security Agency (CISA) has observed that many utilities, particularly smaller ones with limited cybersecurity resources, are left to manage these legacy devices on their own. A 2024 research scan revealed that thousands of PLCs remain searchable and exposed on the public internet.

While no entity has claimed responsibility for the U.K. attack, analysts suggest it may have served as a proof-of-concept to test navigation of vulnerable systems before targeting higher-value infrastructure. The U.K. has tracked Iranian-linked cyber threats for years, including a 2022 attack on Albania’s government services. Tensions have escalated significantly this year, particularly following the U.S.-Israel war against Iran and the death of Supreme Leader Ayatollah Ali Khamenei. Dr. Richard Horne, head of the National Cyber Security Centre, reported in June that his agency managed over 200 attacks on critical infrastructure in the past year, with roughly 75% linked to hostile states such as Iran, China, and Russia.

Photo: Collected