For four days, a UK power station stayed offline after a cyber intrusion. The Telegraph, which broke the story, describes it as the first successful attack of its kind by Iran-linked hackers against British energy infrastructure. Officials have not named the facility, and they say the small plant’s outage never threatened the national grid.
Staff spent four days restoring the facility before the incident was reported to the National Cyber Security Centre, which protects UK critical infrastructure. The government warned power companies about the attack and issued response guidance. The outage was not designed to harm civilians, according to the report; the more likely aim was to prove that hackers tied to Iran’s Islamic Revolutionary Guard Corps can reach UK infrastructure and shut it down at will.
The timing is notable. The attack came as a parallel campaign hit dozens of US wastewater treatment plants across 12 states, forcing boil-water advisories, an effort US government sources attribute to Tehran. Suspected Iranian operations have surfaced across Germany, Poland, Finland, Belgium, and Albania since the country stepped up cyber activity against the West in February. In June, the head of the NCSC put the toll at more than 200 critical-infrastructure attacks handled over the preceding year.
A Cabinet Office risk assessment published last month put the probability of a serious, successful cyberattack on UK infrastructure at between 5 and 25 percent, and warned that AI is making attacks faster, cheaper, and easier to attempt.
For operators of small generation and industrial sites, the incident is a warning that attackers now target facilities far below national grid scale, and that resilience planning must cover them.
