Hackers linked to Iran shut down a British power plant for four days in what is believed to be the first successful Iranian cyberattack to force a UK electricity-generating facility offline, The Telegraph reported.
The attack did not disrupt Britain's broader electricity supply because the facility was relatively small, according to the report. But its apparent success has raised concern among British officials because it demonstrated that hackers affiliated with Tehran may be capable of penetrating and disabling sensitive energy infrastructure.
British authorities have declined to identify the plant, citing security concerns. The Telegraph reported that staff spent four days working to restore the facility after the breach.
The incident occurred around the same time as a wave of cyberattacks against U.S. water infrastructure that affected facilities in 12 states last month and prompted concern at the White House, the newspaper reported.
Following the British breach, the government briefed energy company executives and sent businesses guidance on cybersecurity precautions and their next steps, according to The Telegraph.
The incident was also reported to Britain's National Cyber Security Centre, or NCSC, the public-facing arm of the GCHQ intelligence agency responsible for helping organizations defend critical infrastructure against cyber threats.
While cyberattacks against British institutions are frequent, The Telegraph said no previous hacking operation is believed to have successfully brought a UK power plant to a standstill.
The plant targeted in the attack was small enough that losing it for several days had no meaningful effect on national generating capacity. Britain has dozens of smaller power stations connected to the grid, including gas-fired facilities that may operate only intermittently when additional electricity is needed.
A British government source sought to play down the effect on the grid while acknowledging the incident.
“We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near,” the source told The Telegraph. “It’s a very small scale site, less than a rounding error compared to grid capacity.”
The purpose of the attack remains unclear. The Telegraph reported that it was unlikely to have been designed to cause significant harm to civilians and appears to have attracted little public attention at the time.
One possibility, according to the report, is that the operation was intended as a demonstration of capability, showing that hackers linked to Iran's Islamic Revolutionary Guard Corps could penetrate British systems and shut down sensitive infrastructure.
Attacks on US water systems
The British incident coincided with cyberattacks on dozens of wastewater treatment facilities across the United States.
Those attacks caused flooding and drops in water pressure in some locations, while some authorities told residents to boil water before drinking it.
The first known incident was reported in Minnesota on July 26, followed by breaches in states including Michigan, Georgia, South Dakota and New Jersey, according to The Telegraph.
The FBI initially attributed the incidents to “malicious cyber actors.” U.S. government sources subsequently told media outlets that the activity was believed to have originated in Tehran.
Iran has intensified cyber operations against Western targets since the escalation of the Middle East conflict and particularly since U.S. and Israeli airstrikes began in February, The Telegraph reported.
Suspected Iranian attacks have since been reported in several European countries, including Germany, Poland, Finland, Belgium and Albania, although Israel and other countries in the Middle East remain among the most frequent targets.
British authorities had already been warning organizations to prepare for such activity. In March, the NCSC urged companies to reassess their cybersecurity measures because of the conflict.
Richard Horne, the agency's chief executive, said in June that the NCSC had handled more than 200 attacks against critical national infrastructure during the previous year.
The agency declined to comment specifically on the power plant attack, in keeping with its policy of generally not discussing individual incidents.
Growing threat to critical infrastructure
Britain and the United States have repeatedly warned that state-linked hackers from Iran, Russia, China and North Korea target government networks and critical infrastructure on a regular basis.
Previous major cyber incidents in Britain have disrupted NHS systems, schools and manufacturing operations. Hackers have also targeted retailers and government-related databases, including an attack that compromised Electoral Commission voter records.
But successfully disabling an electricity-generating facility represents a potentially more serious threshold because of the implications for critical national infrastructure.
An assessment by Britain's parliamentary Intelligence and Security Committee last year described Iranian cyber warfare as a “significant area of asymmetric strength,” according to The Telegraph. Iran is believed to spend tens of millions of dollars supporting hacking groups involving hundreds of personnel.
A separate Cabinet Office risk assessment published last month put the likelihood of a serious and successful cyberattack on domestic infrastructure at between 5% and 25%.
The assessment also warned that artificial intelligence could increase the scale and accessibility of such operations by automating attacks and allowing them to be carried out more rapidly and efficiently.
Despite the breach, the British government stressed that the country's electricity network had not been endangered.
“The UK has a highly resilient energy system,” a government spokesman told The Telegraph. “We work closely with the energy sector to protect infrastructure and ensure the highest security standards.”
“This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.”


