Iran hackers vow to target US allies after 4-day UK power plant attack
A four-day shutdown raises bigger questions about how far Iran’s cyber campaign could spread.

Carrington Power Station in England. Christopher Furlong/Getty Images
- Iran-linked hackers knocked a UK power plant offline for four days in July.
- Tehran has now threatened more attacks targeting countries supporting the US.
- Experts warn vulnerabilities repeated across hundreds of similar energy assets could compound into a much larger threat.
- UK lawmakers are now proposing expanded powers to block risky suppliers tied to hostile states.
In what could be the first-ever attack of its kind, British authorities confirm Iran-linked attackers successfully knocked a UK power plant offline for four days last month – as Tehran on Monday vows to expand attacks on US allies.
The attack took place sometime in July, according to government officials, who are now warning the British energy sector to be on high alert for similar attacks.
In response to this specific incident, the NCSC and Department for Energy Security and Net Zero briefed energy CEOs and directly wrote to companies with advice, direction and next steps,the British government said in a statement.
The response comes as the UK government on Monday proposed new powers to block critical infrastructure providers – specifically mentioning energy, water, transport and health – from using technology or suppliers deemed a national security risk, including those tied to hostile states.
The proposal is part of an effort to reform and add to existing UK cyber regulations, and will be presented for scrutiny in Parliament next month.
UK Cybersecurity Minister Liz Lloyd said, under the new powers, "We can act before a threat materialises, not just after the damage is done. By working together with industry, we're putting national security at the heart of how essential services choose their suppliers."
UK power plant knocked offline for four days
The small gas-fired “peaker” plant was closed down for four days around the same time Iranian hackers launched dozens of attacks targeting American water systems across the US, the Financial Times reported.
For security reasons, officials did not disclose the name or location of the “small-scale energy generator,” the exact date it was hit, or how the hackers breached the system.
One of 300 such peaker plants across the UK – used during peak electricity demand as needed – the UK energy department assured the public that the attack had no impact on the national energy system.
“It’s a very small-scale site, less than a rounding error compared to grid capacity,” one UK official said.
Still, the UK’s National Cyber Security Centre (NCSC) is now reportedly involved in the incident response.
The bigger threat to Britain’s power grid
“It's not that Iranian hackers have demonstrated an ability to switch off Britain’s whole electrical grid, but whether the same route into that generator exists across fifty others,” Rob Demain, CEO of e2e-assure, tells Cybernews.
The CEO says the attack proves state-linked actors have both the intent and capability to target relatively ordinary industrial technology and establish access, possibly leading to future attacks.
While one asset is of little consequence, a weakness repeated across hundreds of similar assets could compound into a significant problem because of the technology and suppliers the grid relies on,says Rob Demain, CEO of e2e-assure.
Demain also points out that these types of industrial attacks don't necessarily have to be sophisticated, as critical national infrastructure (CNI) is vulnerable to all sorts of basic security challenges.
He lists exposed internet-facing devices, compromised remote access credentials, vulnerable gateways, and compromised third-party accounts as just a few examples.
“The challenge with securing operational technology (OT) is that it runs on legacy software that can’t be easily patched remotely, and operators always have to weigh up the operational and safety consequences of intervening, as an outage or downtime could threaten safety,” Demain says.
Iran-linked hackers expand beyond US targets
The reveal comes as Iranian leaders vowed on Monday to retaliate against countries allied with the US, coinciding with new threats from the Trump administration to impose fresh sanctions on the enemy nation.
In late July, nation-state hackers linked to the Islamic Republic’s Revolutionary Guard Corps launched a wave of coordinated cyberattacks targeting water and wastewater treatment systems across at least a dozen US states.
The widespread Iranian campaign included 30 cyberattacks on individual water systems in the Upper Midwestern state of Minnesota alone.
The US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued an advisory in April warning critical infrastructure operators of potential Iran-linked attacks on industrial control systems (ICS), specifically naming PLC devices (Programmable Logic Controllers), which are internet-connected computers used to automate facility operations.
In the Minnesota water attacks, hackers managed to change system passwords and IP addresses at some facilities, locking operators out of critical water equipment and forcing manual workarounds.
Large-scale attack could be devastating
Although the “hostile cyber activity” led to disruptions at multiple US water facilities, similar to the UK attack, the public water supply was never at risk.
Even so, Euan Carswell, SOC Team Lead at Barrier Networks, tells Cybernews that despite the UK attack being at a smaller plant and not resulting in any “serious real-world disruption,” it shows that an attack on a large plant is viable.
He says we should also be concerned about the 4-day-long recovery process.
“An outage at a larger provider could leave schools, hospitals, police stations, government buildings, and more without grid power for days,” Carswell says.
Carswell says the damage is obvious: “Homes without power, disruptions to numerous supply chains could lead to economic damage, and for many, a serious risk to life.”
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.