Iranian Hackers Force UK Power Generator Offline for Four Days

The Telegraph reveals the unprecedented cyber breach alongside a wave of Iranian-linked attacks on US water systems across 12 states, as Tehran expands its cyber warfare campaign to critical infrastructure across Western nations

Iranian Hacker backed by Iranian Flag (Graphic: Kurdistan 24)
Iranian Hacker backed by Iranian Flag (Graphic: Kurdistan 24)

ERBIL (Kurdistan 24) - Hackers linked to Iran shut down a British power generator for four consecutive days in what is believed to be the first successful Iranian cyberattack to force a UK electricity-generating facility offline, the Telegraph reported on Saturday, as the same campaign targeted water infrastructure across 12 US states, marking a significant escalation in Tehran's cyber warfare operations against Western critical infrastructure.

British authorities declined to identify the facility, citing security concerns. As Ynetnews confirmed on Saturday, staff at the unnamed plant spent four days working to restore the facility after the breach. The attack did not disrupt Britain's broader electricity supply because the facility was relatively small, but its apparent success alarmed British officials because it demonstrated that IRGC-affiliated hackers may be capable of penetrating and disabling sensitive energy infrastructure, crossing a threshold that previous Iranian cyber operations against British targets had not reached.

Site owner Uniper plans to transform Ratcliffe-on-Soar into a clean energy technology park

A New and More Dangerous Threshold

As Iran International confirmed on Saturday, the incident is believed to be the first successful cyberattack of its kind against a UK facility. Previous major cyber incidents in Britain attributed to Iranian-affiliated actors had disrupted NHS systems, schools, manufacturing operations, retailers, and government-related databases, including an attack that compromised Electoral Commission voter records. Disabling an electricity-generating facility represents a qualitatively more serious threshold because of its implications for critical national infrastructure.

A parliamentary Intelligence and Security Committee assessment described Iranian cyber warfare as a "significant area of asymmetric strength," the Telegraph reported, noting that Iran is believed to spend tens of millions of dollars supporting hacking groups involving hundreds of personnel. A separate Cabinet Office risk assessment published last month placed the likelihood of a successful cyberattack on UK critical infrastructure at its highest assessed level.

Twelve US States Hit Simultaneously

The UK power plant attack occurred around the same time as a wave of Iranian-linked cyberattacks against US water infrastructure that affected facilities in 12 states, prompting concern at the White House, the Telegraph confirmed on Saturday. As Foreign Policy reported on August 13, 2026, water providers in at least seven US states were targeted in a two-week campaign, with officials from the FBI, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency indicating as many as a dozen states could have been impacted.

The hackers targeted components known as programmable logic controllers, which allow utility providers to manage the flow and chemical composition of water supplies to homes and businesses. As CISA confirmed in a July 30, 2026, advisory, in many cases the attackers "modified passwords to lock out operators and disconnected the controllers," forcing some facilities to switch to manual operations. No confirmed contamination of drinking water occurred at any affected facility as of August 5, 2026, with some jurisdictions issuing precautionary boil water notices following pressure-loss events.

As TechTimes reported on August 5, 2026, the attacks revealed a stark structural asymmetry in US critical infrastructure protection. When Iranian hackers probed critical infrastructure for accessible programmable logic controllers, they found far more unlocked entry points in the water sector than in the power sector, because water utilities face no binding federal cybersecurity requirements backed by financial penalties, unlike electricity providers. A volunteer defense program had reached only 21 of approximately 50,000 unprotected small utilities at the time of the attacks.

The situation is further complicated by the imminent expiry on September 30, 2026, of the Cybersecurity Information Sharing Act of 2015, the legislation that provides liability protections enabling private utilities to share threat intelligence with CISA and the FBI, unless Congress acts to renew it.

Part of a Broader Iranian Cyber Campaign

The UK power plant breach and the US water system attacks sit within a documented pattern of expanding Iranian cyber operations against Western critical infrastructure throughout the conflict. The US Justice Department unsealed a 14-count superseding indictment on Tuesday, August 18, 2026, charging 17 members of the IRGC-affiliated Mabna Institute with stealing more than 31 terabytes of data from 144 US universities, 42 US private sector companies, and five government agencies since 2013. The State Department is offering up to $10 million for information leading to five of the defendants who remain at large.

Iran's Supreme National Security Council Secretary Mohsen Rezaei warned on Saturday that Tehran will target the interests of any country helping the United States wage economic warfare against the Islamic Republic, a threat that now carries a concrete cyber dimension given the demonstrated ability of Iranian-affiliated hackers to take British energy infrastructure offline and disrupt water systems across a dozen American states simultaneously.