Iran-Linked Cyberattack Shuts Down UK Power Plant for Four Days
A cyberattack attributed to Iranian-linked hackers forced a small UK power plant offline for four days, raising urgent concerns about the vulnerability of the country's critical infrastructure and energy security.
By Luca Moretti · First published 28 Aug 2026
In brief
- A cyberattack attributed to Iranian-linked hackers shut down a UK power plant for four days in July 2026.
- The incident raised concerns about the vulnerability of the UK's critical infrastructure and prompted urgent security briefings for energy companies.
- The affected power plant has resumed operations, and authorities confirmed the incident was isolated without affecting the national grid.
- The UK government is reviewing cybersecurity measures and discussing improved protocols to prevent future attacks on critical infrastructure.
- Further investigations and potential new regulations for energy companies are expected as the threat of additional cyberattacks looms.
Timeline · 8 moments
Iranian hackers blamed for UK power plant shutdown
The Independent ↗Cyberattack linked to Iran disables UK power plant
CNBC ↗UK energy companies on alert after Iranian-linked hack
Financial Times ↗Iran-linked hackers blamed for cyber-attack on UK power plant
The Guardian - Iran ↗Iranian cyber attack on UK power plant raises concern
ITPro ↗UK power facility disabled for days after suspected state-linked cyberattack
Cybersecurity Dive - Latest News ↗Iran-linked hackers shut down UK power plant for four days
The Next Web ↗Iran-Linked Hackers Reportedly Knock UK Power Plant Offline
Cyber Security News ↗How it started
In July 2026, a small power plant in the United Kingdom was hit by a cyberattack that forced it offline for four days. According to The Guardian and The Independent, this was the first known incident where Iranian-linked hackers managed to successfully disrupt a UK energy facility.
The attack came at a time of heightened global tensions and ongoing cyber activity targeting infrastructure in Western countries. Reports from Security Affairs and CNBC note that this incident coincided with similar attacks on water utilities in the United States, suggesting a broader campaign against critical infrastructure.
How it unfolded
Initial details about the shutdown emerged around August 22, 2026, when The Independent and CNBC reported that the plant had been offline for four days following a cyberattack attributed to Iranian hackers. The exact name and location of the facility were withheld for security reasons, but it was confirmed to be a smaller, gas-powered generator, according to ITPro and in.gr.
The Financial Times reported that energy companies across the UK received urgent briefings from security officials in response to the attack. The incident did not affect the wider national grid or cause customer outages, according to The Guardian and Cyber Security News, but it was still considered a significant escalation in the risk posed to UK infrastructure.
Security Affairs and other outlets highlighted the timing of the attack, noting that it was part of a wave of cyber incidents also targeting water infrastructure in the US. The BBC and The Register confirmed that plant staff worked overtime to restore operations, and there was no evidence of physical damage to the facility.
By August 24, the UK government had acknowledged the incident publicly and began reviewing countermeasures for critical infrastructure. According to The Next Web and The Record by Recorded Future, this included discussions on improved cybersecurity protocols and international cooperation. The US responded by imposing sanctions on Iranian cyber actors, linking their actions to attacks in both the UK and US.
Where it stands
As of late August 2026, the affected UK power plant has resumed operations. Authorities have confirmed that the incident was isolated and did not spread to other parts of the country's energy system. However, the event has prompted a wider review of cybersecurity defenses across the energy sector, especially for smaller facilities.
The Guardian reports that industry leaders and government agencies remain on alert, with new guidance being issued to prevent similar incidents. The attack has also increased pressure on the UK government to address the vulnerabilities of critical national infrastructure.
What to watch
The main question now is whether the UK and its allies can strengthen defenses quickly enough to prevent future attacks. Further investigations are expected, and policymakers are considering new regulations and investment in cybersecurity for energy companies. The possibility of additional, more disruptive attacks remains a concern for both industry and government.


