{"id":1166621,"date":"2026-08-24T12:57:14","date_gmt":"2026-08-24T12:57:14","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/1166621\/"},"modified":"2026-08-24T12:57:14","modified_gmt":"2026-08-24T12:57:14","slug":"iranian-hackers-shut-down-small-uk-power-station-for-4-days","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/1166621\/","title":{"rendered":"Iranian hackers shut down \u2018small\u2019 UK power station for 4 days"},"content":{"rendered":"<p>Hackers linked to Iran\u2019s Islamic Revolutionary Guard Corps (IRGC) are understood to have successfully shut down a \u201csmall\u201d UK power station.<\/p>\n<p>The attack was first reported in The Daily Telegraph newspaper. However, government bodies responsible for the energy network say it has no impact on the wider electricity system.<\/p>\n<p>The power plant was shut down for four days while staff tried to bring it back online, according to the newspaper.<\/p>\n<p>Officials from the Department for Energy Security and Net Zero (DESNZ) are understood to have briefed energy CEOs and directly wrote to companies with advice, direction and next steps.<\/p>\n<p>A government spokesperson said: \u201cThe UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.<\/p>\n<p>\u201cThis [newspaper] story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.\u201d<\/p>\n<p>A\u00a0National Energy System Operator (Neso) spokesperson said: \u201cGreat Britain\u2019s energy system is highly resilient, and Neso continuously reviews and manages threats to its security, including cyber risks.<\/p>\n<p>\u201cThe incident reported had no impact on the wider electricity system. We work closely with DESNZ, NCSC, Ofgem and industry to maintain security and resilience.<\/p>\n<p>\u201cWe do not comment on specific security measures.\u201d<\/p>\n<p>National Preparedness Commission chair Lord Harris told NCE: \u201cThese reports indicate the cyber-vulnerability of key parts of our national infrastructure.<\/p>\n<p>\u201cWe are not alone in this, reports suggest that dozens of water plants in multiple US states have been subjected to concerted cyber attacks in recent months.<\/p>\n<p>\u201cThis \u2013 following on from the cyber-attacks on M&amp;S, the Co-op and Jaguar Land Rover that inflicted huge financial costs [not just] on the businesses concerned but all their supply chains and customers \u2013 highlights why as a nation we have got to take cyber resilience much more seriously.\u201d<\/p>\n<p>Cybersecurity firms e2e-assure, Huntress and Check Point also commented on the incident.<\/p>\n<p>e2e-assure CEO Rob Demain told NCE: \u201cI want to caveat that we still don\u2019t know how this attack was carried out. The plant hasn\u2019t been named, no technical detail has been released, and the NCSC hasn\u2019t commented, so anyone claiming AI was involved in this specific incident is speculating, and I\u2019d include myself in that.<\/p>\n<p>\u201cWhat I can say with confidence is that AI is impacting the direction of travel. AI is lowering the barrier to entry for attackers; it helps them find weaknesses faster, get to grips with unfamiliar industrial and control systems more quickly, and craft and repeat attacks at a scale that used to need a skilled team.<\/p>\n<p>\u201cThis is particularly significant for CNI (critical national infrastructure) because so much of it runs on similar equipment, remote-access arrangements, and suppliers.<\/p>\n<p>He added: \u201cA flaw that once had to be found by hand, one site at a time, can increasingly be hunted across hundreds of near-identical assets at once. The economics of attacking the estate we\u2019ve built are shifting in the attacker\u2019s favour.<\/p>\n<p>\u201cThis is happening now. Attacks on critical infrastructure are already rising, with the NCSC now handling around four nationally significant incidents a week, a large share of which touch national infrastructure, and AI is helping the attackers scale those attacks.<\/p>\n<p>\u201cFor those who design, build, and operate this infrastructure, the takeaway is that they need to assume these systems will be probed, and so to build and run them so abnormal behaviour is visible quickly, treating security as part of the engineering, not something added at the end. Defenders get the same speed from AI that attackers do, but only if we use it.\u201d<\/p>\n<p>Huntress vCISO (virtual chief information security officer) and cybersecurity advisor for EMEA (Europe, Middle East and Africa) Muhammad Yahya Patel said: \u201cThe significance isn\u2019t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.<\/p>\n<p>\u201cThat raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?<\/p>\n<p>\u201cThere is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.<\/p>\n<p>\u201cCritical infrastructure security cannot stop with the organisations considered large enough to be critical. Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem.\u201d<\/p>\n<p>Check Point head of public sector Graeme Stewart said: \u201cThis marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days.<\/p>\n<p>\u201cThat should concern every organisation responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat.<\/p>\n<p>\u201cThe far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.\u201d<\/p>\n<p>He added:\u00a0\u201cWe have to ask: \u2018What happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on?\u2019\u201d<\/p>\n<p>The government confirmed that GCHQ\u2019s (Government Communications Headquarters) National Cyber Security Agency (NCSC) responds to serious cyber incidents impacting UK organisations, providing support to impacted organisations, and coordinating across government.<\/p>\n<p>DESNZ added that plans are in place to ensure the resilience of\u202fUK energy supply\u202fin the unlikely event of significant disruption, regardless of the cause.<\/p>\n<p>The government\u2019s National Risk Register 2026 included a risk profile covering \u2018cyber attack: electricity infrastructure\u2019.<\/p>\n<p>It said: \u201cThe average impact score for risks grouped under the \u2018cyber attacks on infrastructure\u2019 category is 3 (moderate) and the average likelihood score is 4 (5\u201125%).<\/p>\n<p>A moderate impact is quantified as 41-200 fatalities, and\/or 81-400 casualties, and\/or hundreds of millions of pounds in economic costs.<\/p>\n<p>The Network and Information Systems Regulations (2018) already set cyber resilience requirements for the most critical operators across the energy system and the regulations are being updated by the Cyber Security and Resilience Bill, which is currently in Parliament.<\/p>\n<p>The Energy Sector Cyber Security Strategy\u202f explains the government\u2019s plans to further protect the energy system and its consumers, and how the government is working with industry to mitigate cyber risks.<\/p>\n<p>DESNZ is working on an Energy Resilience Strategy for publication later in 2026, which sets out a plan for ensuring the energy system stays resilient today and throughout the energy transition to a wide range of risks, including climate change, technology advancements and geopolitical developments.<\/p>\n<p>Earlier in August, UK and allied spy agencies said <a href=\"https:\/\/www.newcivilengineer.com\/latest\/russian-state-supported-cyber-attackers-targeting-western-energy-organisations-03-08-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">they had exposed Russian state-supported actors which had been targeting Western government and commercial organisations, including in the energy sector<\/a>.<\/p>\n<p class=\"hide-in-mobile-app\">Like what you&#8217;ve read?\u00a0<a href=\"https:\/\/www.newcivilengineer.com\/account\/newsletter\/\" target=\"_blank\" rel=\"noopener nofollow\">To receive New Civil Engineer&#8217;s daily and weekly newsletters click here.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Hackers linked to Iran\u2019s Islamic Revolutionary Guard Corps (IRGC) are understood to have successfully shut down a \u201csmall\u201d&hellip;\n","protected":false},"author":2,"featured_media":1166622,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[3,4],"tags":[323,316699,748,71309,31424,118415,35,393,4884,774,81673,81305,62152,3204,1144,8720,712,16,15,1764],"class_list":["post-1166621","post","type-post","status-publish","format-standard","has-post-thumbnail","category-uk","category-united-kingdom","tag-ai","tag-artificial-intellgience","tag-britain","tag-cyber","tag-cyber-attack","tag-cyber-resilience","tag-energy","tag-england","tag-great-britain","tag-iran","tag-irgc","tag-islamic-revolutionary-guard-corps","tag-national-cyber-security-centre","tag-ncsc","tag-northern-ireland","tag-resilience","tag-scotland","tag-uk","tag-united-kingdom","tag-wales"],"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1166621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=1166621"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1166621\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/1166622"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=1166621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=1166621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=1166621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}