Iran-linked hackers shut UK power plant for four days
Iran-linked hackers shut UK power plant for four days

Iran-linked hackers successfully shut down a UK power generator for four days in July, marking the first time such an attack has been reported, according to The Telegraph. The incident involved an unidentified small energy generator, and while the hackers likely did not intend civilian harm, the attack has raised concerns about the vulnerability of UK infrastructure.

Attack Details and Official Response

The National Cyber Security Centre (NCSC), part of GCHQ, which investigates attacks on infrastructure, declined to comment, as it does not routinely acknowledge individual incidents. The Department for Energy Security and Net Zero told Metro that the power grid was never at risk and the incident had no impact on energy production.

Many small-scale generators only operate for a few hours a week to supplement the grid, such as when wind levels are insufficient to keep turbines spinning. Following the shutdown, department officials briefed energy executives and sent companies advice, direction, and next steps.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

A government spokesperson said: 'The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.'

Broader Cyber Threat Landscape

Security experts have long warned that cyber attacks by foreign countries during wartime are a real threat, not just a Hollywood plot. Fears of Iranian-linked cyber attacks have been elevated since the US and Israel launched a deadly attack on Iran in February, igniting a war.

Factories are particularly vulnerable, according to Steffan Roxrud Thorvaldse, CEO of Qbee, a device management platform. 'Modern factories now operate as “smart” environments where everything is connected, from sensors and cameras to robotics and control systems,' he said. 'That means more ways in for attackers.'

Attackers often gain entry through security vulnerabilities in online systems, such as outdated CCTV camera software. 'From there, attackers can move through networks and potentially interfere with systems that control real-world operations, like factory machinery and production lines,' Thorvaldse added.

Potential Targets and Expert Warnings

Some experts worry that 'Iranian hacktivists'—groups with ties to or sympathy for the regime—could strike. Richard Ford, CTO of cybersecurity firm Integrity360, said: 'It’s impossible to say what companies could be next and whether any will be in the UK, but the chances of it will depend on the UK’s perceived involvement in the war. Although, as with the war, it is not just the US and Israel being targeted but also their partners and allies.'

Other experts caution that hacking groups might pose as Tehran-affiliated to stir tensions or pursue their own agendas. For example, a pro-Russian group breached CCTV footage of an Ipswich go-kart track in March, posting '#TimeOfRetribution' on Telegram, as seen by Metro.

Hacktivists can be hired on the dark web to knock out websites. A common and cheap method is a distributed denial of service (DDoS) attack, which brought down a large portion of the web last November. Such attacks overwhelm a website with requests, making it unresponsive.

Risk Assessment and Preparedness

Despite these concerns, experts tracking Iranian hacking groups have seen little activity, which was expected. The Intelligence and Security Committee, which oversees spy agencies, said last year that while Iran spends millions on hacking groups, it is 'unlikely' they would break into British facilities.

The Cabinet Office estimated in July that the risk of a successful cyber attack against UK infrastructure is between 5% and 25%. Ford emphasized the importance of government preparedness, which officials stress they maintain. 'The worst case, which is less trivial to launch and successfully orchestrate, would be a breach of Critical National Infrastructure (CNI) such as electricity, water supply, health services and food supply, and that could have a myriad of effects and be the highest impact felt by Britons,' Ford said.

Ford cited the Easter breach at M&S last year as an example of severity, where shelves were left bare and customers could not place orders. The incident underscores the need for continued vigilance and investment in cybersecurity across all sectors.

Pickt after-article banner — collaborative shopping lists app with family illustration