A small U.K. power facility was forced to shut down for four days in July after a cyberattack linked to Iran-nexus hackers, government officials have confirmed.
Government officials said the attack, first reported by The Telegraph, was limited to one facility, which they did not identify, and noted there was no wider impact to the country’s energy grid.
“This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system,” a government spokesperson told Cybersecurity Dive.
U.K. Energy Minister Michael Shanks said the government briefed CEOs of multiple energy companies about the situation and shared advice on the “steps they should take to stay secure,” according to a post on X.
The Telegraph report came within days of a warning by the FBI and U.S. Cybersecurity and Infrastructure Security Agency about AI-enabled hackers targeting vulnerable Siemens S7 devices in various industrial settings, including energy and water.
Iran-linked hackers in recent months have been targeting vulnerabilities in programmable logic controllers made by Siemens, Rockwell Automation and Schneider Electric in attacks targeting drinking and wastewater in the U.S. These devices are also used in a wide variety of sectors for monitoring critical functions.
Targeted sector
Researchers at Check Point Software noted the energy sector is one of the most heavily targeted industries across the globe.
“The reason hackers target them is because they are very diverse and distributed, and the ability to get into a critical system, such as the small power plant in this case, can actually be quite easy,” said Gil Messing, chief of staff at Check Point.
Some specific questions about attribution may still arise, as hackers from the group APT Iran denied, in a post on Telegram seen by Check Point researchers, that Iran was involved in targeting the U.K.
U.K. officials did not release specifics about whether PLCs were directly tampered with in the recent attack.
The incident comes at a time when U.K. officials have increasingly focused on business continuity and protecting the security of their critical infrastructure sites from state-linked adversaries.
In June, the CEO of the National Cyber Security Centre said nation-state adversaries accounted for 75% of the 200 attacks against critical infrastructure in the U.K. over the previous 12 months.
U.K. officials have also urged businesses to rethink their security posture with more of a focus on business continuity and resilience, meaning how can they withstand the impact of a cyberattack, noting that adversaries were no longer just trying to steal customer data, but were targeting major providers to purposely disrupt critical functions.
The U.K. went through a series of attacks against major industries, including an attack targeting auto manufacturer Jaguar Land Rover, leading to a disruption from late August to early October 2025. That attack had a $2.5 billion economic impact on the U.K.