Multiple British media outlets, including The Telegraph and Financial Times, reported that Iranian-affiliated hackers temporarily took a power plant in the United Kingdom offline. The incident occurred in July and is described as the first instance of Iranian-linked actors successfully shutting down such a facility in the country. The U.K. National Cyber Security Centre (NCSC) neither confirmed nor denied the reports when contacted for comment.
The incident targeted a small-scale facility and did not affect the national power supply, according to reports. Employees reportedly spent four days restoring control to the plant's systems. The attack coincided with a series of cyber operations in July believed to have targeted water systems in a dozen U.S. states, including Minnesota, Georgia, New Jersey, and South Dakota. In those cases, operators were locked out of systems, resulting in flooding and loss of water pressure.
Both the U.K. and U.S. incidents targeted programmable logic controllers (PLCs), which function as the automated control systems for industrial infrastructure. U.S. and British officials stated that these devices are used in energy, water, manufacturing, hospitals, and transportation. Market research estimates suggest between 12 million and 70 million PLCs are currently in use worldwide, many of which were designed in the late 1960s without modern cybersecurity protections.
For the average resident, these vulnerabilities could manifest as disruptions to daily services such as electricity, water pressure, or transportation timing. The techniques used by hackers are described by CISA as relatively simple, involving the exploitation of default passwords rather than sophisticated software holes. This means that utility customers or hospital patients could experience service outages due to preventable security oversights, such as a facility failing to change a factory-set password on its control hardware.
The U.K. government has tracked an increase in state-linked cyber activity, with NCSC head Dr. Richard Horne stating in June that 75% of the 200 attacks managed by the agency over the past year were linked to hostile states. Security experts suggested these incidents might serve as "proof-of-concept" tests for future attempts against more sensitive targets. While no specific deadline for new security mandates was reported, CISA continues to emphasize that the responsibility for hardening these "unlocked doors" rests with the individual organizations operating the machinery.