Iran-linked attackers knock UK power plant offline
A small UK gas power plant reportedly shut down for about four days in July after a cyber incident, with media reports linking it to Iran-affiliated attackers. Customers never lost power and the wider grid kept running normally throughout.
- Report priority
- High
- Targets
- UK Department for Energy Security and Net Zero
How it works
An attacker can send crafted requests to Iran-linked until Iran-linked stops responding.
What to do
Site operators should watch for updates from the UK Department for Energy Security and Net Zero, which confirmed the cyber incident but has not named the operator or site.
The practical takeaway for energy operators is to remove industrial controllers and engineering interfaces from direct internet access and require secured gateways, named accounts, and multi-factor authentication for any remote support connections.
Technical details
Affected software: UK Department for Energy Security and Net Zero
ThreatMon reported that a roughly 15 MW gas-fired peaking plant in the UK halted operations for about four days in July following a cyber incident, with media accounts attributing it to Iran-linked actors. No malware sample, entry point, exploited flaw, or evidence of direct interference with industrial control systems has been publicly confirmed, and the UK's National Cyber Security Centre has not formally attributed the activity. The UK Department for Energy Security and Net Zero confirmed a cyber incident at a small-scale generator without naming the site. Recovery likely involved verifying controller logic, engineering configurations, and safety functions before restarting equipment.
References
- ppl-ai-file-upload.s3.amazonaws.com · Iran-Linked-Hackers-Reportedly-Knock-UK-Power-Plant-Offline-for-Four-Days.pdf Cyber Security News
- threatmon.io · iran-linked-cyberattack-disrupts-uk-power-generation-facility Cyber Security News
- any.run · threat-intelligence-lookup Cyber Security News
- thehackernews.com · us-sanctions-iran-linked-hackers-behind.html TheHackerNews
- infosecurity-magazine.com · abuse-cursor-agent-ransomware Infosecurity Magazine
- infosecurity-magazine.com · zerotokens-phishing-real-time Infosecurity Magazine
- neuracybintel.com · ringcentral-data-breach-exposes-personal-details-of-16-million-accounts-in-shinyhunters-extortion-campaign NeuraCybIntel
- bleepingcomputer.com · mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft BleepingComputer
- bleepingcomputer.com · toy-making-giant-hasbro-disclose-data-breach-affecting-employees BleepingComputer