Iran-linked attackers knock UK power plant offline

Published August 25, 2026

A small UK gas power plant reportedly shut down for about four days in July after a cyber incident, with media reports linking it to Iran-affiliated attackers. Customers never lost power and the wider grid kept running normally throughout.

Report priority
High
Targets
UK Department for Energy Security and Net Zero

How it works

An attacker can send crafted requests to Iran-linked until Iran-linked stops responding.

What to do

Site operators should watch for updates from the UK Department for Energy Security and Net Zero, which confirmed the cyber incident but has not named the operator or site.

The practical takeaway for energy operators is to remove industrial controllers and engineering interfaces from direct internet access and require secured gateways, named accounts, and multi-factor authentication for any remote support connections.

Technical details

Affected software: UK Department for Energy Security and Net Zero

ThreatMon reported that a roughly 15 MW gas-fired peaking plant in the UK halted operations for about four days in July following a cyber incident, with media accounts attributing it to Iran-linked actors. No malware sample, entry point, exploited flaw, or evidence of direct interference with industrial control systems has been publicly confirmed, and the UK's National Cyber Security Centre has not formally attributed the activity. The UK Department for Energy Security and Net Zero confirmed a cyber incident at a small-scale generator without naming the site. Recovery likely involved verifying controller logic, engineering configurations, and safety functions before restarting equipment.