A small-scale British power facility was forced offline for four days following a cyber attack, in what is believed to be the first successful operation of its kind by hackers affiliated with the Iranian regime against UK energy infrastructure.
Small British Power Plant Forced Offline for Four Days in Unprecedented Cyber Attack
The incident took place in late July according to the Telegraph, with staff working for four days to restore the facility and bring it back online. British authorities have declined to publicly identify the targeted site, citing security considerations.
Government officials emphasized that the disruption remained isolated and did not threaten the country’s wider energy system. A British government source described the site as being less than a rounding error compared to grid capacity
and noted that it fell well below legal notification thresholds for important generators.
Official Response and National Security Concerns
Following the breach, the Department for Energy Security and Net Zero (DESNZ) contacted power companies to advise them about ongoing cyber threats and briefed chief executives with guidance on how to respond. The incident was also reported to the National Cyber Security Centre (NCSC), which operates as part of GCHQ.
While the NCSC declined to comment specifically on the power plant attack, agency head Dr Richard Horne noted that the NCSC deals with around four nationally significant cyber incidents every week. In June, Dr Horne stated that the agency handled more than 200 attacks targeting critical national infrastructure during the previous year, with the majority originating directly or indirectly from hostile nation states.
British and US intelligence agencies have previously warned that state-linked hackers from countries including Russia, China, Iran, and North Korea routinely target government networks and critical infrastructure. Past cyber incidents in the UK have affected National Health Service systems, schools, manufacturing operations at Jaguar Land Rover, and databases belonging to the Electoral Commission. However, security experts note that no previous overseas hacking operation had successfully brought a British power generator to a complete standstill.
Context and Parallels in United States Infrastructure
The timing of the British power plant shutdown coincided with a series of cyber attacks targeting water infrastructure across the United States. These US incidents affected facilities across multiple states, including Minnesota, Michigan, Georgia, South Dakota, and New Jersey, resulting in localized drops in water pressure, flooding, and boil-water advisories. US government sources subsequently indicated that this activity originated in Tehran.
Security analysts suggest that the British power plant attack was likely not designed to cause widespread civilian harm or significant physical damage. Instead, experts indicate that the operation may have served as a capability demonstration by hackers connected to Iran’s Islamic Revolutionary Guard Corps to show they could penetrate Western systems and disable sensitive infrastructure.

The UK maintains a robust network of smaller gas generators and intermittent power stations designed to provide supplementary energy when demand is high or renewable generation drops. Because the targeted facility was relatively small, its four-day shutdown produced no meaningful effect on national generating capacity or the broader electricity supply. DESNZ continues to update its regulatory framework for cyber security and is working on a new energy resilience strategy.
