A cyberattack reportedly forced a small power-generating facility in the United Kingdom to suspend operations for four days, marking what is believed to be the first known incident in which hackers successfully brought a British power plant of its kind to a halt.
The affected facility has not been publicly identified because of security concerns. According to reporting by The Telegraph, the plant is relatively small, and its temporary shutdown did not disrupt electricity supplies or have a significant effect on the UK’s overall power generation.
The incident was reported to the UK’s National Cyber Security Centre (NCSC), although the agency declined to provide details about the case.
A UK government spokesperson confirmed that the incident involved a small-scale energy generator and stressed that the wider energy system was not put at risk. The government said it continues to work with companies in the sector to strengthen protection of critical infrastructure.
The timing of the attack has attracted attention because it occurred alongside cyber incidents targeting water infrastructure across multiple US states. Some of those attacks interfered with remote monitoring systems, while others reportedly contributed to operational problems such as reduced water pressure and subsequent boil-water advisories.
US authorities have linked recent activity targeting industrial systems to Iranian-affiliated hackers. However, the identity of those responsible for the UK power facility incident has not been publicly confirmed.
The Telegraph reported that British officials suspect hackers associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) may have been responsible. According to the report, officials believe the objective may have been to demonstrate an ability to penetrate British critical infrastructure rather than cause widespread disruption. That attribution has not been publicly confirmed by the UK government.
The incident has prompted authorities to warn companies operating within Britain’s energy sector about the threat and provide guidance intended to reduce their exposure. The government is also working on tighter cybersecurity requirements for critical infrastructure.
Concerns about Iranian cyber operations against Western organizations have increased following heightened tensions between Iran and the United States. Security specialists had previously warned that cyberattacks could form part of Iran’s response to US military action.
Separately, the US Department of Justice recently charged 17 Iranian nationals in connection with a long-running cyber campaign targeting universities, private companies, government agencies, and other organizations. US prosecutors allege that some of the activity was conducted on behalf of the IRGC.
The four-day UK shutdown caused no reported disruption to the broader electricity network, but the incident demonstrates that a cyber intrusion can have a direct operational effect on physical energy infrastructure.
