Security & Risk6 minNewsroom

Iran-linked Group Took Down British Power Plant for Four Days in Attack Described as Proof of Concept

Subestação elétrica britânica ao entardecer com luzes de alerta acesas e engenheiro observando o transformador

A report published on August 23 by the Telegraph reveals that hackers linked to the Iranian Revolutionary Guard disrupted a British generator for four days in July. This was the first successful disruption of UK electrical infrastructure.

A report from the Telegraph published on August 23 exposed what British security sources are calling the first cyberattack to take a power plant offline in the UK. The attacker, linked to the Iranian Revolutionary Guard Corps (IRGC), kept a small generator disconnected for four consecutive days in July. Authorities interviewed by CNBC and Cybernews confirmed the incident on Sunday, stating that the national grid was never at risk.


The target has not been disclosed. The government requested confidentiality regarding the identity of the affected plant, and military sources described the operation as a demonstrative exercise, rather than an attempt to cause collective harm. According to the Telegraph, the IRGC's objective was to prove it can penetrate and shut down sensitive assets at will, a calculation compatible with the diplomatic moment: London recently authorized Washington to operate against Iran from British bases, and Tehran signals that it possesses retaliation vectors beyond the conventional military theater.


The National Cyber Security Centre was alerted immediately after the intrusion, and the UK government convened a closed meeting with CEOs of energy operators, in addition to sending written guidance to companies in the sector. There has been no public statement from the operator of the affected plant, and the Ministry of Energy maintained silence when questioned about the case by the Telegraph.


Attack Coincided with Parallel Wave in U.S. Utilities


The British incident was not isolated. Sources cited by the Telegraph report and replicated by Cybernews describe a simultaneous wave against water infrastructure in the United States, which targeted operators in 12 states and reached the White House. None of the American incidents caused prolonged service interruptions, but all were treated as part of the same coordinated campaign.


This joint reading alters the risk calculation for security directors in utilities operators on both sides of the Atlantic. In the UK, the sector had primarily prepared itself against financial ransomware. In the British case, the vector was a state actor with geopolitical signaling objectives, not extortion. This elevates the threat landscape to a level where operational technology (OT) must contend with adversaries willing to accept legal and international sanctions risks in exchange for political messages.


The U.S. Department of Energy had already raised the alert level for water operators in 2024, and a June directive from CISA required mandatory segmentation between corporate IT and industrial control systems. No equivalent directive currently exists in the UK at the regulatory level, only technical guidance from the NCSC.


What to Make of the 'Proof of Concept' Reading


For CIOs of critical operators in continental Europe and Asia, the key point of the report is that the IRGC demonstrated the ability to keep the target unavailable for four full days, enough time to force the activation of backup resources if the target had been larger. The word circulating in Whitehall, according to the Telegraph, is "scalable." The same technique applied to a base load unit would produce a regional blackout.


German and Polish operators had already increased spending on detection in ICS/SCADA systems following the Russian attacks on the Ukrainian grid. In Japan, where Mizuho and MUFG have begun conducting cyber warfare exercises against financial infrastructure, the equivalent concern is that the electricity sector could serve as a stepping stone to attack banks that rely on continuous energy supply. Outside the OECD, Brazil remains partially exposed in the utilities sector: ONS has reinforced perimeter security after the 2023 blackout, but about 40% of distributors still maintain IT/OT convergence without audited logical segmentation, according to a February report from the CERT.br Information Security Study Center.


The new geography of state-sponsored cyber risk against utilities requires a response that most operators still lack: forensic capability in OT with joint forces from the national cybersecurity agency, and a containment manual that accepts stopping production before deciding whether the adversary is a criminal or state actor. As long as this distinction depends on post-fact analysis, four days offline will be the floor, not the ceiling.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk