A small power plant in the United Kingdom was shut down for four days in July following a cyberattack carried out by hackers linked to Iran, according to a report by CNBC citing The Telegraph newspaper.
The incident occurred around the same time that US authorities, including the Federal Bureau of Investigation, warned about malicious cyber actors targeting water facilities across at least seven states. The Cybersecurity and Infrastructure Security Agency, the FBI, the Environmental Protection Agency, and other US agencies attributed that activity to Iran.
A UK government spokesperson declined to identify the affected facility or formally assign blame for the power outage. "This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system," the spokesperson told CNBC. "The U.K. has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards."
The UK government's Department of Energy Security and Net Zero said it briefed energy company CEOs and sent written guidance advising them on next steps following the incident. The department also said it is updating its cybersecurity regulations in response.
The reported attack fits into a broader pattern of Iranian cyber activity that escalated after the United States and Israel launched military operations against Iran on February 28. Shortly after that, cyber experts warned of retaliatory online attacks from Iran targeting US businesses and infrastructure.
On August 18, the US Department of Justice charged 17 Iranians with conducting what prosecutors called a massive cyber theft campaign on behalf of the Islamic Revolutionary Guard Corps and other Iranian entities.
Iran has also been on the receiving end of cyberattacks. In June, blockchain analytics firm Elliptic reported that Iran's largest cryptocurrency exchange, Nobitex, was hacked for more than $90 million. Funds were drained from platform wallets into addresses bearing anti-government messages explicitly referencing the IRGC. Pro-Israel hacking group Gonjeshke Darande, also known as Predatory Sparrow, claimed responsibility for that attack.
The UK power plant incident and the simultaneous US warnings point to a coordinated pattern of Iranian cyber operations targeting energy and water infrastructure in allied nations. The Trump administration has been preparing additional measures to isolate Iran's economy, though further pressure may involve confronting China, which remains the dominant buyer of Iranian oil, according to Bloomberg.
The UK government has not announced any formal attribution or response specific to the July power plant shutdown.
