READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Iranian-Linked Hackers Knocked a Small UK Power Plant Offline for Four Days in July

Iranian-Linked Hackers Knocked a Small UK Power Plant Offline for Four Days in July
A small British power generator was taken offline for four days last month by hackers with links to Iran, marking what The Telegraph reports may be the first successful cyber shutdown of a UK power facility. The government says the site was too small to matter to the national grid, but the incident lands alongside a wave of Iranian-linked attacks on US water systems and growing warnings from the UK's own cyber agency.

A small power plant in the UK was shut down for four days last month after a cyber attack by hackers linked to Iran, according to reporting from The Daily Telegraph that has since been confirmed in substance by the BBC and the UK government.

The government has not named the facility or its location, citing security concerns. Officials say the plant was a small-scale generator, not one of the country's major power stations, and that the outage never threatened the broader electricity supply.

A government source told The Telegraph the site was "nowhere near" the legal thresholds that require major generators to report cyber incidents, calling it "a very small scale site, less than a rounding error compared to grid capacity." The Department for Energy Security and Net Zero echoed that in a statement to the BBC, saying "at no point was there a risk to the wider energy system."

Still, the shutdown is being treated as significant. Times Now, citing The Telegraph, reports it is believed to be the first time hackers have succeeded in bringing a British power facility to a complete standstill, despite prior disruptions to NHS systems, schools, and industrial sites. Staff reportedly fought for four days to bring the plant back online, according to details relayed by the Manchester Evening News and the Daily Mirror.

The National Cyber Security Centre, the public arm of GCHQ responsible for defending UK critical infrastructure, was notified of the incident but has declined to comment further, a standard practice for individual cyber cases. The NCSC's chief executive, Richard Horne, said in June that the agency handled more than 200 attacks against critical national infrastructure over the prior year, according to Times Now.

The attack is believed to have happened in July, around the same time hackers targeted water and wastewater systems across at least seven, and by some FBI counts twelve, US states. The Epoch Times reported that Michigan joined that list after the FBI issued a warning to states about attempts to tamper with operational technology at water systems between July 27 and July 30. Michigan's Department of Environment, Great Lakes and Energy said it received a small number of reports consistent with the FBI's warning but confirmed no public health impact.

The FBI and EPA said the water-system attackers targeted internet-connected programmable logic controllers, specifically Rockwell Automation and Allen-Bradley MicroLogix models, changing passwords and IP addresses after gaining remote access. Officials in Braham, Minnesota reported an attack on July 27 that disrupted well and treatment plant controls without affecting water quality. Federal agencies have urged utilities nationwide to pull these controllers off the open internet and put them behind firewalls.

No source in this reporting has drawn a formal, attributed link tying the UK power plant hack to the same operators behind the US water system attacks. They are described as happening around the same time, not as the same campaign, and readers should treat that as an open question rather than a confirmed connection.

In response to the UK incident, the government briefed the chief executives of British power companies and issued written guidance to businesses on cyber security measures, according to the Express, the Mirror, and upday. DESNZ says it is updating cyber security regulations and developing a new energy resilience strategy later this year.

The timing matters. Iran has ramped up cyber operations against Western targets since the US and Israel launched airstrikes in the Middle East in June 2025, according to Times Now. The NCSC warned British organizations in March to shore up their defenses because of the conflict. The BBC noted that despite that bracing for retaliation, "there has been little activity so far" from Iranian state-linked hackers against the UK, which makes this incident notable as a rare confirmed hit rather than a routine occurrence.

There is a reasonable case for skepticism about how alarmed the public should be here. The plant affected was, by the government's own account, a minor generator of the kind Britain has dozens of, built to supply short bursts of power during demand spikes, not baseload capacity the grid depends on. A four-day outage at a facility that small genuinely may be, as officials put it, a rounding error.

But a rounding error that still took four days to fix, at a facility government insiders themselves flagged as being below mandatory reporting thresholds, raises a fair question about what happens if the next target isn't below that threshold. Neither DESNZ nor the NCSC has disclosed what specific vulnerability let the hackers in, whether it mirrors the programmable logic controller weaknesses the FBI flagged in the US water attacks, or whether any UK generator operators have been ordered to make specific changes beyond the general advisory sent out after the incident. Those details remain undisclosed as of this reporting.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
BBCCyber attack shut down small power plant
center-left
The Daily MirrorUK power plant 'shut down for four days' after major Iran-linked cyber attack
right
Epoch TimesMichigan Reports Water System Cyberattacks, Joining 7 Other States
right
Times NowIran's Cyber War Hits UK: Power Plant Taken Offline for Four Days
right
ExpressIranian hackers ‘shut down UK power plant’ for days after major cyber attack
unknown
updayFour days offline: Iranian cyber attack disables British power plant in historic breach | The latest National and International News
unknown
Manchester Evening NewsUK power plant 'shut down for four days' after Iran-linked cyber attack