"Iranian hackers" shut down a UK power station. The next incident could be much worse

Cyberattack that forced a small generator offline sparks fears about the vulnerability of critical infrastructure.

Share
"Iranian hackers" shut down a UK power station. The next incident could be much worse

Iran has been blamed for a cyberattack that shut down a UK power plant for four days.

Last month, a small gas generator was pulled off the grid as defenders battled assailants who were later linked to Tehran.

After the attack was first reported on Sunday, the UK government announced plans to secure supply chains by blocking businesses from buying technology from potentially dangerous suppliers.

Although the incident was small in scale and did not come anywhere near disrupting the national grid, it is the latest in a series of incidents across the West that remind us of the frightening vulnerability of critical infrastructure.

Graeme Stewart, head of public sector at Check Point, said: “Cybersecurity is rapidly becoming about something much bigger than protecting information. It is about protecting the systems that allow a modern country to function and finding out how resilient those systems are during a major attack would be far too late.

"The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat. The far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.

"We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on."

Shared vulnerabilities

The attack took down one of the UK’s small gas-fired “peaker” plants, which typically have a capacity of about 15 megawatts, connect to local electricity distribution networks and run semi-automatically without employees on site, switching on when the network signals that additional electricity is needed.

Britain has roughly 300 such plants spread across the country, with a total capacity of between 4GW and 7GW.

Physical decentralization does not eliminate concentration risk. Britain's roughly 300 peaker plants may be geographically separate, but often rely on the same programmable logic controllers (PLCs), communications modules, firmware, remote-access systems, or suppliers, meaning thousands of separate machines can still share the same vulnerability.

Britain is also heavily dependent on foreign technology and equipment — another point of weakness. China supplied 35.3% of all UK electrical-equipment imports in 2025, up from 24.1% in 2017. Separate evidence submitted to Parliament found that the number of critical-sector commodity groups in which Britain was strategically dependent on China jumped from 42 in 2020 to 102 in 2025.

READ MORE: The EU has “kill switches” in its critical systems. Can digital sovereignty fix them?

\This reliance on tech from potentially hostile nations has contributed to fears that "kill switches" are hidden in devices critical to the functioning of modern society. MPs have warned that more than 70% of the world's cellular IoT modules are manufactured in China and raised fears that remote access or malicious firmware updates could theoretically be used to disable equipment in British critical infrastructure.

Matt Caswell, executive director of the OpenSSL Foundation and principal software engineer, said defenders need to understand the technology and dependencies sitting underneath critical services in order to prevent further attacks.

He added: “Modern infrastructure contains layers of software from different suppliers and open-source projects. Organisations need enough visibility to know which dependencies really matter before an attack happens, so they can understand their exposure and respond quickly when something goes wrong.

“For the UK, this is also a wider resilience question. Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on. That needs to be part of the conversation about how we protect essential services.”

Utilities under attack

The incident took place against a backdrop of increasingly ambitious and impactful attacks.

In April, US agencies warned that an Iranian-affiliated group was disrupting PLCs across water, energy and government facilities. The campaign targeted these industrial controllers to disrupt operations and cause financial losses to victims.

The attacks then spread into other operational technology. Hackers suspected of links to Iran targeted fuel-management and monitoring systems at gas stations, while a wave of attacks against US water infrastructure reached at least 12 statesin July and August.

Some utilities lost remote monitoring and control, with attackers gaining access to pumps, valves and water-pressure controls. Federal investigators suspect an Iranian connection but have not formally attributed the campaign.

Four days before reports emerged of the attack on a British power plant, the NSA, FBI and other agencies warned that hackers were using AI-generated exploitation scripts to target internet-exposed Siemens S7 PLCs, technology used across energy, water, manufacturing and other critical infrastructure sectors.

The agencies described the activity as an “active threat,” although they did not attribute that campaign to Iran.

Denis Calderone, CTO of Suzu Labs, has been tracking Iran-linked operations against Western targets since April.

"The pattern keeps escalating," he said. "There is a real and growing threat to critical infrastructure."

He called on the UK government to follow Poland by releasing key details of the attack to help operators protect themselves.

Calderone continued: "Was a PLC directly exposed to the Internet? Was remote access compromised? Did attackers manipulate the physical process, or did operators shut the plant down defensively after an IT compromise? What control would have broken the attack chain?

“Don’t tell me this was historic and then redact the history. Explain the attack path, identify the class of failure, and give other operators something they can actually use to defend themselves."

Neena Sharma, cybersecurity expert at Filigran, said Iran's "playbook" has historically been based on "symbolic, deniable, low-consequence disruption rather than escalatory attacks that risk a kinetic response."

"This four-day outage at a small-scale generator fits that pattern precisely: enough to demonstrate capability and signal resolve, not enough to trigger any significant response. If anything, the choice of target might itself be the message. Critical infrastructure risk isn't concentrated at the 'crown jewel' substations anymore, it's distributed across hundreds of smaller, less-monitored assets that scale with the energy transition."

James Neilson, SVP of Global at OPSWAT, backed up this warning and said: “We’ve seen a significant development in the cyber capabilities of Iran-linked groups. Iranian state-sponsored and hacktivist groups have shifted from espionage towards high-impact disruption to support IRGC efforts, making critical infrastructure an obvious target.

"IT systems, internet connectivity and transient devices can all be used to gain access to ICS/OT infrastructure. Iranian groups will often hunt out default credentials immediately to achieve rapid, low-noise access."

The fingerprints of Tehran?

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the incident raises two important questions.

He asked: "Why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents? There is also a potential visibility gap.

"If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.

"The question now has to be whether Britain is genuinely ready if something more serious follows."

Another important question is whether the attack can truly be blamed on Iran.

Donald McFarlane, advisory board member at Xcape, Inc, said: “‘Iran-linked’ is not the same thing as proving that the Iranian government directed the attack. We should distinguish what happened to the plant, who conducted the intrusion, and by which nation-state it was instructed. Attribution in cyberspace is an analytical conclusion, not something you read off the source IP address."

Cian Heasley, principal consultant at Acumen Cyber, also said: "Attribution for the incident is by no means concrete; the Iran link originates from press reporting while the UK government has declined to attribute blame or name the site affected.

"Adding to the confusion, the pro-Iranian hacktivist group calling itself 'APT Iran' has publicly denied any involvement, insisting Britain is not among its targets, that its activity was directed only at the United States, and that only six US states were affected rather than wider numbers reported.

"This denial should be read with considerable caution, though. The group is widely assessed by security researchers to be a rebrand of CyberAv3ngers, the IRGC-linked actor with a documented history of information operations and exaggerated claims, so a denial fits its established playbook and settles very little either way."

Is the US next?

After a string of attacks that have caused limited disruption, defenders now have to consider what would happen if attackers attempted something much larger.

Seemant Sehgal, founder and CEO of BreachLock, said: "The visible coordination across a UK facility and dozens of US water systems in the same window indicates that these environments are being mapped and tested well before the disruptive payload arrives."

If attackers do escalate, the consequences could be far more serious.

John Strand, owner of Black Hills Information Security, Inc., said: "This particular breach scares me because of how much further behind the United States power grid is compared to Europe.

"An attack like this could potentially have a far greater impact in the US."

Strand said modernization of America's power grid has been "painfully slow" due to factors including legislative capture and incentives that helped utility companies make money from generating and selling power, but not updating aging infrastructure.

“Then there’s the interconnected nature of the U.S. power grid," he added. "A relatively small problem at a substation can create ripple effects across multiple areas of the grid. That’s what makes this such a serious wake-up call. When you combine that interconnectedness with the incredibly slow pace of infrastructure modernization, especially across the power grid, I’m very concerned."

READ MORE: Security firms hit back at Trump’s call to hack back against international crime gangs

Dan Bird MBE, EMEA field CTO at Horizon3, said: "Cyber gives adversaries a way to create strategic impact below the threshold of war. A well-timed attack on an energy supplier, manufacturer, logistics provider or smaller operator can disrupt the supply links that keep the economy moving at low cost and potentially cause repercussions.

“The next attack may not be limited to a single site. It could hit multiple smaller operators at once, or a more significant part of the energy system. That is why UK organizations in critical supply chains must not assume they are too small or too peripheral to be targeted."

The aftershocks of critical infrastructure attacks

Although the actual damage was limited, even a small attack can have a psychological impact.

Ric Derbyshire, principal security researcher at Orange Cyberdefense, said: "The incident creates a second-order cognitive effect across wider society by showing that UK energy infrastructure can be reached and disrupted through cyber activity. That perception can shape how people view the resilience of critical infrastructure and potentially undermine public trust and confidence."

It also reminds us that a kinetic war in another part of the world is no longer anywhere near as distant as it used to be.

Trevor Dearing, senior director of critical infrastructure at Illumio, said: "Cyberattacks are increasingly part of geopolitical conflict, and the energy sector is particularly vulnerable. Ageing infrastructure combined with increasingly connected IT, operational technology and smarter grids creates more entry points for attackers and greater potential for disruption."

The challenge for Western defenders is that adversaries can strike at the heart of critical systems while evading reliable attribution, potentially causing impacts across society.

Richard Ford, CTO at Integrity360, said: "Critical infrastructure and operational technology are attractive targets because disruption can have consequences far beyond the systems that are initially compromised."

This time it was a small attack. But defenders need to prepare for a more serious incident as geopolitical tensions boil over.

Andrew Lintell, general manager, EMEA at Claroty, said: "Attackers do not need to bring down the national grid in order to cause disruption. Taking even a single facility offline highlights why cyber risk in critical infrastructure needs to be measured not only in terms of data loss, but in downtime, service availability, and the ability to keep essential processes running.

"Our own research into 200-plus attacks against cyber-physical systems found that 82% involved attackers using VNC clients to remotely access exposed, internet-facing assets, not sophisticated exploits or zero-days, but weak or default credentials and insecure legacy protocols."

Follow Machine on LinkedIn