
A British power plant was forced offline for four days in what The Telegraph reported on Saturday was an unprecedented cyberattack linked to Iran.
The incident is believed to be the first known case in which hackers affiliated with the Iranian regime successfully shut down a power facility in Britain. Officials reportedly consider it the most successful cyberattack of its kind against UK energy infrastructure.
The attack occurred last month, around the same time as a series of cyberattacks against water infrastructure in the United States that affected 12 states and raised concerns at the White House, according to The Telegraph.
British officials have declined to identify the affected facility, citing security considerations. The plant is understood to have been relatively small, however, meaning the disruption did not threaten Britain's overall electricity supply or energy production. Staff worked for four days to restore the facility.
The government subsequently briefed the chief executives of power companies and contacted businesses with guidance and instructions on how to respond. The incident was also reported to the National Cyber Security Centre (NCSC), the public-facing cybersecurity arm of GCHQ.
The NCSC declined to comment specifically on the incident. British and US intelligence agencies have repeatedly warned that hackers linked to Russia, China, Iran and North Korea regularly target critical infrastructure and government systems.
Previous cyberattacks have disrupted NHS systems, schools and industrial operations, including manufacturing lines at Jaguar Land Rover. Foreign hackers have also stolen customer data from retailers and voter information from the Electoral Commission.
Despite those incidents, there had previously been no known case of a cyberattack bringing a British power plant to a standstill.
The attack does not appear to have been intended to cause widespread harm to the public and reportedly went largely unnoticed, according to The Telegraph. One possibility being examined is that the operation was intended to demonstrate that hackers connected to Iran's Islamic Revolutionary Guard Corps could penetrate British systems and disable sensitive infrastructure.
Britain has dozens of smaller power stations connected to the national grid. Many are gas-fired facilities that operate only intermittently, such as when low wind speeds reduce electricity generation. A prolonged shutdown at one such plant would not affect the wider grid, while some industrial sites and hospitals maintain independent generators.
The NCSC advised British organizations in March to reassess their cybersecurity measures amid the conflict. Its chief executive, Richard Horne, said in June that the agency had dealt with more than 200 attacks targeting critical national infrastructure during the previous year.
A Government source said, “We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near. It’s a very small scale site, less than a rounding error compared to grid capacity."
A Government spokesman said, “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards. This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system."
