A small power plant in the United Kingdom was forced to shut down for four days following a cyberattack suspected to have been carried out by hackers linked to Iran, raising fresh concerns over the vulnerability of critical infrastructure amid heightened geopolitical tensions. The attack took place in July and forced staff to spend four days restoring the facility, according to reports. British authorities have not disclosed the identity or location of the plant because of security concerns. While the incident did not disrupt Britain's wider electricity supply, it is believed to be the first known case in which Iran-affiliated hackers have successfully forced a UK power-generating facility offline.
Plant offline for four days
The targeted facility was a relatively small gas-fired "peaker" plant with a capacity of around 15MW, according to the Financial Times. Such facilities are typically brought online during periods of high electricity demand and can operate with limited staffing through automated control systems.
The attack reportedly compromised systems sufficiently to require the plant to be taken offline while its operators worked to restore normal functioning.
Officials have stressed that the facility was not considered critical to the functioning of Britain's national electricity network and that its four-day shutdown did not threaten the wider power supply.
Nevertheless, the ability of suspected state-linked hackers to disrupt a physical energy asset has prompted concern because cyber operations against infrastructure can potentially move beyond data theft and cause real-world interruptions.
Energy companies put on alert
Following the incident, the British government warned energy companies about the threat and provided guidance on strengthening their defences. The National Cyber Security Centre (NCSC), which is part of GCHQ, has been involved in the response.
Energy companies have subsequently been placed on heightened alert, with executives advised to review the resilience of their systems against potential attacks.
The NCSC said it had not received reports of outages affecting regulated operators, suggesting the incident involved a facility outside that category.
The episode comes as governments increasingly worry about cyberattacks on operational technology — the digital systems used to control machinery, industrial equipment and utilities.
Smaller generating facilities can rely heavily on programmable logic controllers and remote management systems, potentially creating points of vulnerability if those systems are exposed or inadequately protected.
Iran links under scrutiny
The attack has not been publicly attributed to a specific hacking group, and British authorities have stopped short of formally blaming the Iranian government.
However, reports have linked the intrusion to hackers associated with Iran amid an increase in cyber activity targeting Western infrastructure.
Suspected Iran-linked attacks have also been reported against infrastructure elsewhere, while hackers believed to have connections with Tehran have previously targeted industrial control systems.
The British incident reportedly occurred around the same period as cyber intrusions targeting water infrastructure across several US states, further intensifying scrutiny of Iran-linked cyber groups.
Cyber threat grows
The shutdown highlights how geopolitical confrontation can spill into digital attacks against civilian infrastructure even when the immediate physical consequences remain limited.
Britain has faced cyber threats attributed to a range of state-linked actors in recent years, with energy, government, healthcare, manufacturing and other strategically important sectors viewed as potential targets.
The latest breach has therefore drawn attention less because of the amount of electricity lost than because hackers apparently succeeded in forcing an operating energy facility offline.
The UK government has maintained that its electricity system remains resilient and that it is working with energy companies to strengthen protection against evolving cyber threats.
For Britain's energy sector, however, the four-day shutdown offers a warning that cyberattacks are no longer confined to stealing information or disrupting websites: a successful intrusion can potentially interfere directly with the infrastructure that produces and supplies energy.