
Iran-linked hackers shut down British power plant for four days in July cyberattack
A July cyberattack attributed to Iran-linked hackers knocked a small British power plant offline for four days without causing wider disruption to the electrical grid, according to government statements.
Four-day generator shutdown
A cyberattack linked to Iran forced a British electricity generation facility offline for four days in late July. British authorities withheld the name and exact location of the site for security reasons, describing it as a small-scale generator whose output represents a negligible fraction of national supply. While technical staff worked for four days to restore operational control, the disconnection caused no power outages and did not affect electricity distribution across the national grid.
The incident represents the first recorded case of hackers affiliated with the Iranian regime, including elements connected to the Islamic Revolutionary Guard Corps (IRGC), taking a British energy facility out of service. Government officials briefed chief executives of commercial energy operators following the incident, distributing technical guidance and security recommendations to protect industrial control environments.
This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.
Wider infrastructure campaigns
The British outage occurred alongside a series of intrusions targeting municipal water networks in the United States. On 26 and 27 July, attackers struck more than 30 local water utilities across Minnesota, causing localized flooding and pressure drops that led some communities to issue boil-water advisories. The activity later spread to water treatment facilities across 12 US states. On 19 August, US federal authorities published an alert warning of active exploitation attempts against Siemens programmable logic controllers used across utility networks.
- US and Israel begin airstrikes on Iranian territory
- UK NCSC warns organisations of potential collateral cyber risks from Iran-linked groups
- NCSC reports thwarting over 200 cyberattacks on UK critical national infrastructure
- Cyberattacks strike more than 30 local water systems across Minnesota
- Donald Trump states he does not believe Iran carried out the US water utility attacks
- US authorities issue an alert regarding active attacks on Siemens utility controllers
- Reports disclose the four-day shutdown of a British electricity generator
Although several reports linked the water utility intrusions to Iranian actors, official assessments have differed. During a press gathering at Camp David on 31 July, US President Donald Trump stated that he did not believe Iran was responsible for the water utility disruptions.
Geopolitical friction and military bases
The cyber activity followed military escalation earlier in the year, when the US and Israel began air operations against targets inside Iran in February. In response to British decisions allowing American aircraft to conduct defensive sorties from UK bases, the IRGC warned that any installation supporting operations against Iran would be treated as a target.
any base used for aggression against Iranian territory constitutes a legitimate target for our forces
British Prime Minister Andy Burnham was notified of a decision to extend the basing agreement with Washington, maintaining the policy of permitting defensive US flights while withholding support for offensive strikes. Suspected Iranian cyber intrusions have also been reported by authorities in Germany, Poland, Finland, Belgium, and Albania, though activity remains concentrated in Israel and the Middle East.
UK cybersecurity readiness
The National Cyber Security Centre (NCSC) reported that it received no disruption alerts from regulated power stations during the July incident. In March, the agency warned domestic infrastructure operators to prepare for collateral cyber activity linked to the regional conflict. NCSC chief executive Richard Horne stated in June that the agency had defended against more than 200 cyberattacks directed at critical national infrastructure in the period up to May.
Past intrusions into British networks have caused operational interruptions for the National Health Service, schools, and private industrial facilities, including an attack attributed to Russian groups that caused 2.2 billion euros in damage to Jaguar Land Rover manufacturing lines. Energy officials continue working with utility operators to prevent further incursions into industrial control networks.


