Iran-Linked Hackers Take U.K. Power Plant Offline for First Time

August 25, 2026 at 3:34 pm
2 min read

Iranian-affiliated hackers successfully but temporarily took a power plant offline in the United Kingdom, according to multiple British media outlets including The Telegraph and Financial Times.

The attack, which occurred in July but was only recently disclosed, marks the first time hackers with ties to Iran have managed to shut down such a critical energy facility in the country.

Vulnerabilities in Industrial Control Systems

In both the British incident and parallel attacks targeting water systems across 12 U.S. states including New Jersey, Minnesota, Georgia, and South Dakota, hackers targeted computers known as programmable logic controllers, or PLCs.

According to U.S. officials and British sources, these devices act as the brains of automated industrial systems spanning energy, water, and manufacturing plants worldwide.

Simple Tactics Expose Massive Security Gaps

Security researchers and the U.S. Cybersecurity and Infrastructure Security Agency noted that the hackers used surprisingly simple techniques, such as scanning for exposed devices and exploiting default passwords rather than deploying complex exploits.

This strategy is more akin to looking for unlocked doors versus high-tech hacking, experts pointed out, noting that many older units still in use were manufactured as early as the late 1960s without modern cybersecurity in mind.

Impact and Future Threats

During the incident, the affected British system remained offline for 4 days as employees worked frantically to restore control.

While officials have not disclosed the specific facility, confirming only that it was a small-scale plant causing no broader power shortages, experts warn these operations may serve as proof-of-concept tests for future, high-value attacks.