Overview
A British power plant was shut down for four days after a cyber attack carried out by hackers linked to Iran, according to reports from the Telegraph, as cited by multiple outlets. The exact location of the facility has not been disclosed for security reasons, but sources told the Telegraph that the site was disabled "while staff fought to bring it back online" after the attack.
The incident is believed to have occurred in late July, and it has been described as an "unprecedented" cyber attack. The Jerusalem Post, citing the Telegraph, reported that it is believed to be the first successful attack of its kind in the UK.
Impact and Government Response
The affected plant was not among the nation's largest energy sites, and the shutdown had no impact on the UK's wider power supply or energy generation. A government source told the Telegraph that the site was below legal notification thresholds for important generators, describing it as "a very small scale site, less than a rounding error compared to grid capacity."
A government spokesman said: "The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards. This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system."
In response to the incident, the government briefed the chief executives of power companies and issued written guidance to businesses with advice and next steps.
Connection to US Attacks
The attack on the UK power plant coincided with a series of attacks on US water infrastructure that affected 12 states and raised concern at the White House. The Jerusalem Post reported that the attack occurred during a reported Iranian cyberattack that targeted over 30 municipal water systems in Minnesota and several other US states.
US President Donald Trump stated in late July that he did not think Iran was behind the US cyberattack. Joe Slowik, director of threat research for Dataminr, told the Washington Post at the time that similar attacks have occurred in water and energy systems across the United States since the beginning of the war with Iran. Kurt Gaudette of Dragos noted that the attacks were generally against "low-hanging fruit" such as small utilities with default passwords and internet-exposed controllers.
Perspectives
- UK Government: The government has emphasized the small scale of the affected site and the resilience of the UK's energy system, asserting that there was no risk to the wider energy supply at any point.
- Security Experts: Experts quoted in the Jerusalem Post highlight opportunistic targeting of weak systems, such as small utilities with poor security, and note a broader pattern of attacks on critical infrastructure linked to the war with Iran.
- US Officials: President Donald Trump disputed Iranian involvement in the US cyberattacks, suggesting uncertainty about the attribution of those specific incidents.