Suspected Iranian Hackers Shut UK Power Plant for Four Days
A British power plant was offline for four days in July 2026 after a suspected Iranian cyberattack, according to The Telegraph and Help Net Security. The incident was reported to the National Cyber Security Centre and did not impact the national grid.

Suspected Iranian hackers caused a British power plant to shut down for four days in July 2026. The incident was reported to the National Cyber Security Centre and did not noticeably affect the UK power supply.
Incident Details
The Telegraph reported that the plant was offline for four days during July 2026, a period that coincided with a coordinated cyberattack on more than 30 community water utilities in the United States. Those US attacks followed a warning about Iranian cyber activity against energy, water and government networks.
The incident was reported to the National Cyber Security Centre (NCSC). According to the publication, the outage had no noticeable effect on the UK’s power supply.
Government Response
Michael Shanks, the UK Minister of State in the Department for Energy Security and Net Zero, said the cyber incident affected a “small-scale energy generator”, but did not name the facility. He added that after the incident the government briefed energy CEOs and shared further advice on steps to stay secure.
Shanks highlighted ongoing collaboration with industry, regulators and the NCSC to assess threats and strengthen protections. He noted increased engagement in recent months, including the Energy Resilience and Security Taskforce, which he chairs and which key industry players actively participate in.
Expert Analysis
James Griffiths, founder of UtopianKnight Consultancy and former adviser at GCHQ, called the incident a wake-up call for the critical national infrastructure community. He noted that the plant took four days to return online, which could be considered a quick recovery depending on the attack’s scale.
Griffiths raised questions about the plant’s interconnection with the national grid and whether attackers could have moved to other areas. He said that public disclosure of lessons learned would help illustrate how vulnerable smaller power plants can be.
Dan Bird, EMEA Field CTO at Horizon3.ai, warned that the UK should view the attack as a clear message that critical infrastructure and its supply chains are now fair game. He said cyber provides adversaries a way to create strategic impact below the threshold of war and that provable attribution remains a challenge.
Bird added that future attacks might target multiple smaller operators or a larger part of the energy system. He urged UK organisations in critical supply chains not to assume they are too small or peripheral to be targeted.
Tim Williams, CEO of London-based cybersecurity company Quod Orbis, expects electricity, power and water to be targets for more attacks. He said resilience will depend on real-time knowledge of whether controls designed to protect critical operations are working and on clear accountability when they are not. Williams called for continuous assurance to become part of how organisations manage operational resilience, especially as state-linked actors look for ways to exploit digital systems.
Broader Threat Landscape
Last year the UK government introduced the Cyber Security and Resilience Bill, which aims to improve resilience against cyber threats by forcing public services and digital service providers to strengthen their digital defenses. The bill is currently moving through Parliament and is expected to become law in late 2026.
Iran is not the only nation whose cyber offensive capabilities target energy delivery. Ukraine’s power grid has been repeatedly targeted by Russia-backed APT group Sandworm since the start of the war. Late last year the Polish government revealed suspected Sandworm attacks aimed at crippling Poland’s energy infrastructure.
In July 2026 the EU and UK imposed sanctions against Russia’s cyber operators - both individuals and companies - over efforts to destabilise Europe by targeting public services and critical infrastructure in many European countries.





