Hackers linked to Iran managed to shut down a British power station for four days in July 2026. The story was revealed by Telegraph newspaper on August 22, 2026. That it took this long to become public knowledge immediately says two things. First, it was not a large power plant, as the effect would be immediately noticeable, and second, the authorities wanted to keep news of the attack as low-key as possible.
Other newspapers (eg the BBC, the Guardian and the Financial Times) have since published their own stories, largely based on the Telegraph’s account. There was virtually no information from the expected official sources, such as the NCSC. The BBC report commented: “While the Western cyber security world is braced for attacks by either the state (of Iran) or state-linked hackers as a result of the conflict with the US this year, there has been little activity so far.”
This last point is clearly wrong. Since the outbreak of the US/Israeli war, cyber groups linked to Iran have attacked numerous targets in the US (water, critical infrastructure and military-related assets), Israel (military, government, energy, healthcare and others), GCC targets in the UAE, Bahrain, Kuwait, Qatar, Saudi Arabia and Europe (Cyprus, Romania and now the UK). This doesn’t mean ‘low activity so far’, so UK expansion should not be downplayed. And in general, cybersecurity experts don’t discount it.
“It’s not about the size of the facility, it’s that the cyber attack turned into four days of real-world downtime. This raises an important question: why did it take four days to recover, and are smaller operators sufficiently prepared to contain and recover from these incidents?” asks Muhammad Yahya Patel, vCISO and Cyber Security Advisor for EMEA Hunter.
A related question worth asking is whether Iranian hackers are probing the UK’s defenses for increased aggression – and whether this attack could be repeated. “Loss of a facility like this can be managed well and is reportedly not a serious risk to stability, but these are often very repetitive attacks that can be deployed at scale,” posted Phil Tonkin, field technical director at Dragosis LinkedIn.
Rafael Narezi, CEO of centershas a similar concern. He points out that attackers aren’t worried about the size of the target – they’re looking for trusted access and capabilities. “What worries me about this incident is not necessarily the size of the generator affected, but how many others may be out there… This particular incident may not have had consequences for the wider grid, but the next one may be different.”
He points out: “There are thousands of distributed assets across the UK that increasingly contribute to the way our energy system works. Individually, many may seem insignificant. Collectively, their sustainability is of huge importance.”
Graham Stewart, head of public sector at Check Point, warned: “This marks a major escalation in the conflict in Iran, as a hostile state cyber threat has reportedly reached the UK’s energy infrastructure and caused a physical shutdown lasting four days. This should concern any organization responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was not affected does not remove the threat. Very the more serious point is what the attackers appear to have demonstrated: an ability to penetrate the UK’s energy infrastructure and shut it down.

Since the start of the Iran war, Iranian hackers have attacked critical infrastructure of the US and its allies. Apart from Israel, the UK is generally seen as a major ally of the US. Britain cannot be surprised that it was targeted – indeed, the bigger surprise is that this appears to be the only known successful Iranian cyber attack to date. Apart from the lack of official information (almost all information is based on a single report in the Telegraph), concern should also focus on the apparent lack of resilience of the hacked power plant. Four days to recover in such an important part of CNI is just too long. And if the attack happens again and Iran increases similar attacks, the UK needs to prepare.
Connected: US indicts 17 Iranian hackers and offers $10 million rewards for 5 of them
Connected: Cyberattacks on Minnesota water systems under investigation as officials warn of Iranian hackers
Connected: US warns of Iranian hackers targeting Siemens, Schneider and Rockwell ICS devices
Connected: LA Metro cyberattack linked to state-sponsored hackers in Iran