Sunday, 23 August 2026 Newsarchy UK live index
NewsarchyUKUK
Every UK story. Mapped, sourced, and explained where it matters.
World

Iranian hackers shut down British power plant in four-day cyberattack

A small-scale British power plant suffered a four-day shutdown following a cyberattack linked to Iranian hackers in July, though officials stressed it posed no threat to the wider electrical supply.

Iranian hackers shut down British power plant in four-day cyberattack
Iranian hackers shut down British power plant in four-day cyberattack

A British power plant suffered a complete four-day shutdown following a targeted cyberattack linked to Iranian hackers, according to reports covered by the New York Post and the Mirror. The breach marks what is believed to be the first known instance of Iranian hackers successfully disabling a power-generation facility in the UK.

Staff scrambled to bring the installation back online while the facility remained disabled for four days, according to reporting by the Mirror. Authorities have withheld the exact location and name of the site for security reasons.

Media additions

Image via mirror.co.uk
Image via mirror.co.uk

The targeted installation is a small-scale power generator. Because of the limited capacity of the site, officials stressed that the outage never posed a threat to the nation's wider electrical supply or overall energy generation, as reported by the New York Post.

A government source described the scale of the facility in stark terms to reporters. The source explained that the site sits well below the thresholds requiring important generators to legally notify authorities of cyber activity, as noted by the Mirror, adding that the output of the affected site is less than a rounding error compared to overall grid capacity.

The incident itself occurred in July. Following the breach, the event was formally reported to the National Cyber Security Centre (NCSC), which operates as the public-facing arm of GCHQ, according to the New York Post.

The breach has rattled the domestic energy industry and intensified scrutiny over foreign cyber threats. The NCSC previously issued warnings earlier in the year advising companies to prepare for potential actions by Iran-linked hackers amid escalating geopolitical tensions involving Iran, the United States, and its allies, as detailed by the New York Post.

International parallels emerged simultaneously. The July breach in Britain coincided with a wave of cyberattacks targeting water infrastructure across at least 12 states in the US, according to the New York Post. In Minnesota, local officials directly blamed Iran for triggering brief automated shutdowns and forcing the issuance of boil-water notices, according to the New York Post.

UK authorities have sought to reassure the public that critical infrastructure remains secure despite the alarming nature of the breach. Officials warned that domestic infrastructure faces ongoing risks, compounded by the adoption of artificial intelligence tools that make cyberattacks faster and easier to deploy, according to the New York Post.

In response to the growing threat level, the government took direct administrative action. Officials briefed the chief executives of major power companies and distributed formal written guidance outlining advice, direction, and necessary next steps, according to the Mirror.

A government spokesman issued a formal statement emphasizing the robust nature of national defenses:

"The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards."

Government spokesman, via New York Post and Mirror

The spokesman reiterated that the incident was strictly confined to a small-scale energy generator and that at no point was there a risk to the wider energy system, as reported by the Mirror.

Incident Overview

  • Timing: July
  • Target: An unidentified small-scale power generator in Great Britain
  • Duration of Outage: Four days while staff fought to bring it back online
  • Impact: No effect on the UK's wider power supply or energy generation, with output described as less than a rounding error compared to grid capacity
  • Involved Agencies: National Cyber Security Centre (NCSC) and GCHQ
  • International Context: Occurred concurrently with cyberattacks on water infrastructure across 12 US states, prompting concern in the White House and specific actions in Minnesota

Related stories