The Plain Record

Neutral daily news — clear headlines, complete facts.

World

Reports Link Iranian Hackers to Four-Day Shutdown of U.K. Power Plant

Reports from The Telegraph and Financial Times state that Iranian-linked hackers temporarily disabled a small U.K. power plant in July using simple techniques.

Published August 24, 2026 at 1:35 PM EDT

The short answer

Reports from The Telegraph and Financial Times state that Iranian-linked hackers temporarily disabled a small U.K. power plant in July using simple techniques. Multiple British media outlets, including The Telegraph and Financial Times, reported that Iranian-affiliated hackers temporarily took a power plant in the United Kingdom offline.

Reports Link Iranian Hackers to Four-Day Shutdown of U.K. Power Plant

The Facts

Who
Iranian-affiliated hackers, U.K. power plant operators, NCSC, and CISA.
What
A cyberattack reportedly linked to Iran temporarily took a U.K. power plant offline.
When
July; reported in August 2026.
Where
United Kingdom
Why
The incident highlights vulnerabilities in programmable logic controllers (PLCs) used in critical infrastructure worldwide.

Timeline of what happened

Key dates and decisions, in the order they occurred.

  1. 2022

    U.K. officials condemn Iran for cyberattack on Albania government services.

  2. June 2024

    NCSC head discloses 200 attacks on U.K. infrastructure in previous year.

  3. July 2024

    Reported attack on U.K. power plant and U.S. water systems occurs.

Multiple British media outlets, including The Telegraph and Financial Times, reported that Iranian-affiliated hackers temporarily took a power plant in the United Kingdom offline. The incident occurred in July and is described as the first instance of Iranian-linked actors successfully shutting down such a facility in the country. The U.K. National Cyber Security Centre (NCSC) neither confirmed nor denied the reports when contacted for comment.

The incident targeted a small-scale facility and did not affect the national power supply, according to reports. Employees reportedly spent four days restoring control to the plant's systems. The attack coincided with a series of cyber operations in July believed to have targeted water systems in a dozen U.S. states, including Minnesota, Georgia, New Jersey, and South Dakota. In those cases, operators were locked out of systems, resulting in flooding and loss of water pressure.

Both the U.K. and U.S. incidents targeted programmable logic controllers (PLCs), which function as the automated control systems for industrial infrastructure. U.S. and British officials stated that these devices are used in energy, water, manufacturing, hospitals, and transportation. Market research estimates suggest between 12 million and 70 million PLCs are currently in use worldwide, many of which were designed in the late 1960s without modern cybersecurity protections.

For the average resident, these vulnerabilities could manifest as disruptions to daily services such as electricity, water pressure, or transportation timing. The techniques used by hackers are described by CISA as relatively simple, involving the exploitation of default passwords rather than sophisticated software holes. This means that utility customers or hospital patients could experience service outages due to preventable security oversights, such as a facility failing to change a factory-set password on its control hardware.

The U.K. government has tracked an increase in state-linked cyber activity, with NCSC head Dr. Richard Horne stating in June that 75% of the 200 attacks managed by the agency over the past year were linked to hostile states. Security experts suggested these incidents might serve as "proof-of-concept" tests for future attempts against more sensitive targets. While no specific deadline for new security mandates was reported, CISA continues to emphasize that the responsibility for hardening these "unlocked doors" rests with the individual organizations operating the machinery.

Summaries are written by The Plain Record to state the facts of a story plainly and without political slant. See our editorial standards, or report a correction.

← Back to the front page

Questions readers ask

What happened: Reports Link Iranian Hackers to Four-Day Shutdown of U.K. Power Plant?

A cyberattack reportedly linked to Iran temporarily took a U.K. power plant offline.

Who is involved?

Iranian-affiliated hackers, U.K. power plant operators, NCSC, and CISA.

When did this happen?

July; reported in August 2026.

Where did this happen?

United Kingdom

Why does this matter?

The incident highlights vulnerabilities in programmable logic controllers (PLCs) used in critical infrastructure worldwide.