Suspected Iran-linked cyberattack shuts down UK power generator for four days
- Event Year
- 2026
- Reliability
- Likely But Unconfirmed
- Country
- United Kingdom
- Industry
- Power and Utilities
- Attack Type
- Targeted Attack
Description
In July 2026, a small-scale UK power generation facility was forced offline for four days following a cyberattack. The incident was reported by The Telegraph on August 22-23, 2026, citing unnamed sources describing suspected Iranian involvement. UK Energy Minister Michael Shanks confirmed that the incident affected "a small-scale energy generator" and that the government had briefed energy company chief executives on defensive measures, stating there had been no risk to the wider energy system. The UK National Cyber Security Centre did not publish an advisory. The facility's name, location, generation type, and the specific OT systems affected were not disclosed. Dragos CEO Robert M. Lee publicly cautioned against premature Iranian attribution, noting susceptibility to false-flag operations. No Iranian group claimed the attack, and no official attribution had been issued as of late August 2026.
Impact
Single small-scale UK power generation facility offline for four days in July 2026; UK government confirmed no impact to the wider electricity grid; financial loss and generation capacity not disclosed; no injuries or public safety incidents reported.
Sources
- https://www.securityweek.com/iran-linked-hackers-shut-down-uk-power-plant-for-four-days/
- https://www.cybersecuritydive.com/news/uk-power-facility-disabled-Iran-cyberattack/828599/
- https://www.helpnetsecurity.com/2026/08/24/uk-power-plant-cyberattack/
- https://tech-insider.org/iran-linked-hackers-uk-power-plant-cyberattack-2026/
- https://www.packetlabs.net/posts/disabled-uk-power-facility