A cyber attack linked to Iranian hackers temporarily shut down a U.K. power plant for four days in retaliation for the country allowing the United States to launch attacks from its bases. The U.S. used RAF Fairford in Gloucestershire and Diego Garcia in the Indian Ocean to launch “defensive” attacks against the Islamic Republic.
The United Kingdom operates approximately 2,059 combined heat and power (CHP) plants and five nuclear power stations to meet its energy needs.
Meanwhile, British authorities said the cyber attack did not affect power supply and that the country’s power grid was “highly resilient.”
Cyber attack shuts down U.K. power station
A spokesperson for the Department for Energy Security and Net Zero (DESNZ) said the cyber attack targeted a small-scale energy generator but declined to disclose which power station was affected or where it was located. However, he assured the British public that the attack on the power plant posed no threat to the country’s electricity grid and that the U.K. energy grid was resilient.
“This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system,” the spokesperson said.
He added that the government had taken additional steps to address the incident seriously and that the generator was “tiny” compared to what would be classified as a “power plant.”
He also noted that the department had advised energy-generating companies on steps to secure power stations.
The National Cyber Security Centre (NCSC) and other regulators were also involved and were working to enhance the security of the national grid.
Meanwhile, the cyber attack on the power plant is the first incident attributed to Iranian hackers in the United Kingdom. However, the government has not attributed the cyber attack to any specific state-sponsored or hacktivist group. The government also avoided attributing the cyber attack to Iran, which has been blamed for attacking the US critical infrastructure.
Authorities also have not disclosed which power plant or attack vector the threat actors exploited, pending ongoing investigations.
“This particular breach scares me, not necessarily because it happened in the United Kingdom, but because of how much further behind the United States power grid is compared to Europe,” said John Strand, Owner, Black Hills Information Security. “Modernization of the U.S. power grid has been painfully slow for a number of reasons, including legislative capture and the basic economics of how utilities make money. They make money from generating and selling power. They don’t necessarily make money from updating aging infrastructure.”
“Then there’s the interconnected nature of the U.S. power grid, with Texas being the notable exception. A relatively small problem at a substation can create ripple effects across multiple areas of the grid. That’s what makes this such a serious wake-up call,” added Strand. “When you combine that interconnectedness with the incredibly slow pace of infrastructure modernization, especially across the power grid, I’m very concerned. I think an attack like this could potentially have a far greater impact in the United States than what we’re seeing in Europe.”
Iranian hackers continue to target Western critical infrastructure
Cybercriminals have frequently targeted power stations to cause disruptions and coerce organizations into paying a ransom. In particular, Iranian hackers have frequently targeted critical infrastructure by compromising programmable logic controllers.
The UK has experienced cyber attacks in the past. In 2025, hackers breached North Hyde Substation in London, disrupting power supply for nearly 70,000 residents.
In July 2026, the FBI and CISA warned about Iranian hackers expanding the list of targeted programmable logic controllers to compromise critical infrastructure. In May 2026, Iranian hackers compromised gas stations across the United States by manipulating automatic tank gauge (ATG) readings.
In 2023, the pro-Iranian hacking group CyberAv3ngers breached a Pennsylvania water utility after compromising internet-exposed industrial control systems. According to the attackers, every Israeli-made PLC was a legitimate target.
In May 2026, industry experts attributed the cyber attack on the Los Angeles transit system to Iranian hackers, who exfiltrated over 700 Gigabytes of data, including backups, files, and emails.
Still in 2025, a pro-Russian group targeted a power plant in Sweden, which authorities said was linked to the ongoing Ukraine War. That same year, hackers targeted a renewable energy power station and a large combined heat and power plant in Poland and attempted to deploy wiper malware.
In July 2026, the FBI and CISA warned about hackers expanding the list of targeted devices used to compromise critical infrastructure organizations.

