Hackers linked to Iran’s Islamic Revolutionary Guard Corps (IRGC) are understood to have successfully shut down a “small” UK power station.
The attack was first reported in The Daily Telegraph newspaper. However, government bodies responsible for the energy network say it has no impact on the wider electricity system.
The power plant was shut down for four days while staff tried to bring it back online, according to the newspaper.
Officials from the Department for Energy Security and Net Zero (DESNZ) are understood to have briefed energy CEOs and directly wrote to companies with advice, direction and next steps.
A government spokesperson said: “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.
“This [newspaper] story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.”
A National Energy System Operator (Neso) spokesperson said: “Great Britain’s energy system is highly resilient, and Neso continuously reviews and manages threats to its security, including cyber risks.
“The incident reported had no impact on the wider electricity system. We work closely with DESNZ, NCSC, Ofgem and industry to maintain security and resilience.
“We do not comment on specific security measures.”
National Preparedness Commission chair Lord Harris told NCE: “These reports indicate the cyber-vulnerability of key parts of our national infrastructure.
“We are not alone in this, reports suggest that dozens of water plants in multiple US states have been subjected to concerted cyber attacks in recent months.
“This – following on from the cyber-attacks on M&S, the Co-op and Jaguar Land Rover that inflicted huge financial costs [not just] on the businesses concerned but all their supply chains and customers – highlights why as a nation we have got to take cyber resilience much more seriously.”
Cybersecurity firms e2e-assure, Huntress and Check Point also commented on the incident.
e2e-assure CEO Rob Demain told NCE: “I want to caveat that we still don’t know how this attack was carried out. The plant hasn’t been named, no technical detail has been released, and the NCSC hasn’t commented, so anyone claiming AI was involved in this specific incident is speculating, and I’d include myself in that.
“What I can say with confidence is that AI is impacting the direction of travel. AI is lowering the barrier to entry for attackers; it helps them find weaknesses faster, get to grips with unfamiliar industrial and control systems more quickly, and craft and repeat attacks at a scale that used to need a skilled team.
“This is particularly significant for CNI (critical national infrastructure) because so much of it runs on similar equipment, remote-access arrangements, and suppliers.
He added: “A flaw that once had to be found by hand, one site at a time, can increasingly be hunted across hundreds of near-identical assets at once. The economics of attacking the estate we’ve built are shifting in the attacker’s favour.
“This is happening now. Attacks on critical infrastructure are already rising, with the NCSC now handling around four nationally significant incidents a week, a large share of which touch national infrastructure, and AI is helping the attackers scale those attacks.
“For those who design, build, and operate this infrastructure, the takeaway is that they need to assume these systems will be probed, and so to build and run them so abnormal behaviour is visible quickly, treating security as part of the engineering, not something added at the end. Defenders get the same speed from AI that attackers do, but only if we use it.”
Huntress vCISO (virtual chief information security officer) and cybersecurity advisor for EMEA (Europe, Middle East and Africa) Muhammad Yahya Patel said: “The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.
“That raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?
“There is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.
“Critical infrastructure security cannot stop with the organisations considered large enough to be critical. Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem.”
Check Point head of public sector Graeme Stewart said: “This marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days.
“That should concern every organisation responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat.
“The far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.”
He added: “We have to ask: ‘What happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on?’”
The government confirmed that GCHQ’s (Government Communications Headquarters) National Cyber Security Agency (NCSC) responds to serious cyber incidents impacting UK organisations, providing support to impacted organisations, and coordinating across government.
DESNZ added that plans are in place to ensure the resilience of UK energy supply in the unlikely event of significant disruption, regardless of the cause.
The government’s National Risk Register 2026 included a risk profile covering ‘cyber attack: electricity infrastructure’.
It said: “The average impact score for risks grouped under the ‘cyber attacks on infrastructure’ category is 3 (moderate) and the average likelihood score is 4 (5‑25%).
A moderate impact is quantified as 41-200 fatalities, and/or 81-400 casualties, and/or hundreds of millions of pounds in economic costs.
The Network and Information Systems Regulations (2018) already set cyber resilience requirements for the most critical operators across the energy system and the regulations are being updated by the Cyber Security and Resilience Bill, which is currently in Parliament.
The Energy Sector Cyber Security Strategy explains the government’s plans to further protect the energy system and its consumers, and how the government is working with industry to mitigate cyber risks.
DESNZ is working on an Energy Resilience Strategy for publication later in 2026, which sets out a plan for ensuring the energy system stays resilient today and throughout the energy transition to a wide range of risks, including climate change, technology advancements and geopolitical developments.
Earlier in August, UK and allied spy agencies said they had exposed Russian state-supported actors which had been targeting Western government and commercial organisations, including in the energy sector.