Iran-linked hackers shut down a minor UK power plant for four days in July, marking the first time such a group has knocked one offline, according to The Telegraph. The incident involved an unidentified small energy generator, and the power grid was never at risk, with no impact on energy production, the Department for Energy Security and Net Zero told Metro.
Incident Details and Response
The National Cyber Security Centre, part of the spy agency GCHQ, declined to comment, as it does not routinely acknowledge individual incidents. Department officials briefed energy bosses and wrote to companies with advice, direction, and next steps following the shutdown.
Many small-scale generators only run for a few hours a week to top up the grid, such as when there is not enough wind to keep turbines spinning. A government spokesperson said: 'The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.'
Broader Cyber Threats and Expert Warnings
Security experts have long warned that a cyber attack by a foreign country during wartime is not just the stuff of cheap Hollywood films. Fears of Iranian-linked attacks have been high since the US and Israel launched a deadly attack on Iran in February, igniting a war.
Factories are easy targets for cyber attacks, Steffan Roxrud Thorvaldse, CEO of Qbee, a device management platform, told Metro. 'Modern factories now operate as “smart” environments where everything is connected, from sensors and cameras to robotics and control systems,' he said. 'That means more ways in for attackers.' Attackers can gain entry by slipping into security holes in online systems, such as a CCTV camera using out-of-date software, and then 'move through networks and potentially interfere with systems that control real-world operations, like factory machinery and production lines,' he added.
Potential Targets and Risk Assessment
Some experts worry that 'Iranian hacktivists', groups with ties to or sympathy for the regime, could strike. Richard Ford, CTO of the cybersecurity specialist Integrity360, said: 'It's impossible to say what companies could be next and whether any will be in the UK, but the chances of it will depend on the UK's perceived involvement in the war. Although, as with the war, it is not just the US and Israel being targeted but also their partners and allies.'
Other experts worry that hacking groups could pose as Tehran-affiliated to stir up tensions or pursue their own agendas, such as a pro-Russian group that pried open CCTV footage of an Ipswich go-kart track in March, posting '#TimeOfRetribution' on Telegram. Hacktivists can be hired on the dark web to knock out websites, often using distributed denial of service (DDoS) attacks, which brought down a massive chunk of the web last November.
Despite these concerns, experts who track Iranian hacking groups have seen little activity, which was expected. The Intelligence and Security Committee said last year that while Iran spends millions on hacking groups, it is 'unlikely' they would break into British facilities. The Cabinet Office said in July that the risk of a successful cyber attack against UK infrastructure is between five and 25%.
Ford says it is vital the government is prepared for cyber attacks. 'The worst case, which is less trivial to launch and successfully orchestrate, would be a breach of Critical National Infrastructure (CNI) such as electricity, water supply, health services and food supply, and that could have a myriad of effects and be the highest impact felt by Britons,' he said. 'M&S is a very good example of a cyber attack,' he added of the Easter breach last year, 'particularly in terms of severity and impact where shelves were left bare and customers unable to place orders.'



