A small power-generating facility in the United Kingdom was knocked offline for four days in what is believed to be the first successful cyberattack to bring a British power plant to a standstill, The Telegraph reported on August 22, with Cybernews confirming details on August 23, 2026. The government has not identified the plant, citing security concerns, but officials say the outage did not affect the wider UK electricity supply.
Suspected IRGC-linked operation
British officials believe the operation was aimed at demonstrating that hackers linked to Iran's Islamic Revolutionary Guard Corps (IRGC) can reach into critical UK infrastructure, rather than at causing large-scale disruption for civilians. The incident was reported to the UK National Cyber Security Centre, which declined to comment on the record.
Paired with US water-sector attacks
The UK compromise appears to line up with a concurrent wave of cyber intrusions against US water utilities across at least 12 states last month. Some of those breaches took operators offline for remote monitoring or triggered boil-water advisories and pressure loss, with US officials attributing the campaign to Iranian threat actors. On August 18, the US Justice Department charged 17 Iranian nationals with running a cyber campaign against more than 300 universities, private companies, government agencies and NGOs, many of them tasked by the IRGC.
UK sharpens sector-specific rules
A UK government spokesperson said the country has "a highly resilient energy system" and works closely with the sector to protect infrastructure, and that ministers are drafting tougher cyber-security rules for energy operators. The plant incident is likely to accelerate the timetable for a new critical-infrastructure regime, adding to a busy month for the sector that already included Cisco's CVSS 10.0 Crosswork and Secure Workload patches and Shell's Cl0p ransomware data-theft disclosure.
Reporting based on coverage from Cybernews, The Telegraph and CNBC.
