Iranian hackers cripple UK power plant for four days
A cyber attack blamed on Iran-linked hackers forced a small UK power plant shut down for four days last month, raising fresh concerns about the security of Britain’s energy infrastructure. The Government said the incident posed no threat to the wider electricity system, while businesses have been urged to review and strengthen their cyber defences.
The affected site has not been publicly identified because of security concerns. Officials have described it as a small-scale energy generator rather than one of Britain’s major power stations, and there was no wider interruption to national electricity supplies.
The attack, first reported by The Telegraph, is believed to have happened in July. The facility remained out of operation for four days while staff worked to restore its systems.
It is being treated as a significant incident because reports suggest it could be the first known case in which hackers linked to Iran have successfully forced a British electricity-generating facility offline. However, the attribution has been reported by media and officials have not publicly disclosed detailed technical evidence identifying those responsible.
Government says national power supply was not at risk
The Department for Energy Security and Net Zero sought to reassure the public after details of the attack emerged.
A department spokesman said the incident involved a “small-scale energy generator” and that “at no point was there a risk to the wider energy system”. Officials said Britain’s energy network remained resilient and that the Government continued to work with the sector to protect key infrastructure.
Following the breach, power company executives were briefed and businesses were given advice about measures they could take to strengthen their systems. The National Cyber Security Centre, which helps protect the UK against serious online threats, has also been involved in wider work to improve the resilience of the energy sector.
The NCSC had already warned organisations to review their cyber security following the escalation of conflict in the Middle East. It said Iranian state and Iran-linked cyber groups retained the capability to carry out attacks and advised organisations facing greater risks to increase monitoring and examine possible weaknesses in their networks.
Britain’s concerns about Iran-linked activity are not limited to cyber security. New Daily Prime previously reported on three Iranian men charged in Britain over alleged activities linked to a foreign intelligence service. The charges were allegations and were being handled through the courts.
Cyber attacks put critical infrastructure under pressure
The latest incident comes as Britain faces a growing number of cyber threats against businesses and important national services.
The NCSC said in June that it had dealt with more than 200 incidents affecting UK critical infrastructure and organisations supporting it in the year to May 2026. Around three-quarters were believed to have links to hostile state actors.
The Government’s Energy Sector Cyber Security Strategy, published in May, also warned that Iran-based actors remained active online and had targeted industrial control systems — the computer technology used to operate machinery and infrastructure.
New Daily Prime has previously reported on the wider threat from hackers targeting major businesses in Britain and the United States, including attacks linked to the hacking group Scattered Spider.
The reported power plant breach also comes against the background of continuing tensions involving Iran and the United States. Cyber security agencies have warned that international conflicts can increase the risk of digital attacks against governments, businesses and infrastructure.
For households, the key point is that the four-day shutdown did not cause a national power shortage and officials have not announced any action that consumers need to take. For businesses, particularly those involved in energy and other essential services, the incident is another warning to keep software updated, monitor networks and follow official NCSC cyber security guidance.
The attack shows that even a relatively small energy facility can become a target during periods of international tension. Although Britain’s wider electricity system was not disrupted, the incident has renewed questions about how well smaller generators and other infrastructure operators are protected from increasingly persistent cyber threats.
Related news




