‘Security Journal UK’ has received a number of responses to the recently announced cyber attack and subsequent four-day shut down of a small UK powerplant. Mark Fletcher, reports.
Initially reported in ‘The Telegraph’, the attack that took place in July, was allegedly carried out by hackers affiliated to the Iranian regime.
No further details were given by either the UK Government or the National Cyber Security Centre – both citing security reasons.
However, Michael Shanks MP, minister for energy, said on X: “The Telegraph’s reporting today relates to a cyber incident affecting a small-scale energy generator.
“To be clear: there was no threat to the wider grid and nobody lost power.
“We have one of the most resilient energy systems in the world.
“The generator in question is tiny especially compared to what most of us would class as a power plant/station.
“That being said the generator and the Government took the incident seriously.
“After the incident, we briefed energy CEOs and shared further advice with companies on the steps they should take to stay secure.
“We work continually with industry, regulators and the National Cyber Security Centre to assess threats and strengthen protections.
“This follows increased engagement in recent months including the Energy Resilience and Security Taskforce which I chair and which key players from across industry actively participate.
“Our Energy Sector Cyber Security Strategy sets out how we are working to enhance cyber security.
“Later in 2026 our wider Energy Resilience Strategy will go further to secure us against a wide range of risks and ensure our resilience for the future.”
Industry commentary has been landing on our news desk throughout the morning:
Ric Derbyshire, Principal Security Researcher at Orange Cyberdefense, said: “A four-day outage at a UK generation site is still significant even when the lost capacity, as in this case, is small.
“The incident creates a second-order cognitive effect across wider society by showing that UK energy infrastructure can be reached and disrupted through cyber activity. That perception can shape how people view the resilience of critical infrastructure and potentially undermine public trust and confidence.
“The incident also sits within a wider increase in hostile-state and state-aligned activity against national infrastructure. The NCSC has warned repeatedly about this trend and about the growing use of cyber operations as part of wider geopolitical pressure.
“While the actors and specific technology affected in this incident are not confirmed, the shape of the event seems to follow a broader pattern of actors chasing the metaphorical cyber-dragon for bigger and more shocking impacts, including disruption of OT within CNI. If this escalation continues, defenders should expect more actors to pursue overt disruption of physical infrastructure.”
James Griffiths, Principle Consultant and Founder of UtopianKnight, said:“A UK power plant hacked and linked to the Iranian Regime was unfortunately inevitable. Although we don’t know which power plant was targeted and successfully shut down, what is clear is that this is a wake-up call for the rest of the critical national infrastructure (CNI) community.
“Unfortunately, this is something that most will have been worried about happening for a long time. The under-investment in protecting our CNI in the UK has always been an issue with legacy and aged systems running the core of what we take for granted. Power.
“Although nothing has been released about how this happened, what is interesting is that it took four days for the power plant to come back online. Now, depending on the scale of the attack against the plant, this could be deemed as quite a quick recovery to operations. Quite a few other UK and global power suppliers will now be looking to harden their defences.
“Clearly had this been an attack at a larger power plant, then this could have led to major disruption, affecting the National Grid and causing blackouts. But the more serious question is how interconnected was that power plant to the rest of the national grid network and could the attackers have been able to move to other areas?
“If made public, it will be interesting to see what lessons are identified so we can all really understand how frail some of the smaller power plants are.”
Cian Heasley, Principal Consultant, Acumen Cyber, said: “The reported cyberattack that took a small UK power-generating facility offline for four days is a significant moment for the sector, not because of its scale, which the government has been at pains to stress was absolutely tiny measured against overall grid capacity, but because of what it signals.
“Attribution for the incident is by no means concrete; the Iran link originates from press reporting while the UK government has declined to attribute blame or name the site affected. Adding to the confusion, the pro-Iranian hacktivist group calling itself “APT Iran” has publicly denied any involvement, insisting Britain is not among its targets, that its activity was directed only at the United States, and that only six US states were affected rather than wider numbers reported. This denial should be read with considerable caution, though.
“The group is widely assessed by security researchers to be a rebrand of CyberAv3ngers, the IRGC-linked actor with a documented history of information operations and exaggerated claims so a denial fits its established playbook and settles very little either way. Important to note that this group does not officially speak for the Iranian government.
“Attribution aside, the more consequential point for the UK energy sector is that the significance of this incident lies in the precedent rather than the impact. A successful, if limited, intrusion into a power-generating asset demonstrates intent and a degree of capability against British energy infrastructure. We can compare this to the pattern seen in the concurrent US campaign, where attackers targeted internet-exposed industrial controllers protected by weak or default credentials.
“The considered and sensible response is not alarm over grid resilience, which held, but a renewed focus on OT security fundamentals across operators of all sizes. There urgently needs to be work done in removing controllers from direct internet exposure, enforcing strong credential management, segmenting IT from OT, and rehearsing manual fallback and recovery.
“The NCSC and Department for Energy Security and Net Zero (DESNZ) briefing of energy CEOs suggests this is being taken seriously, and operators would do well to treat it as an opportunity to consider their security controls and test their own assumptions before the next attempt succeeds against something that matters more.”
Simon Hodgkinson, Semperis Strategic Advisor and former bp CISO, said: “Many of the cyberattacks on electricity and water utilities are opening salvos, carried out either to gauge the effectiveness of a nation’s cybersecurity defenses or to plant backdoors for future attacks.
“It isn’t surprising that Semperis found in a recent research report that 62% of electricity and water utilities in the UK and U.S. were victimised by cyberattacks. These attacks are likely a precursor of future disruption. Utilities should adopt an assume-breach mindset and prepare to respond to and securely recover from attacks that target and hide in critical parts of the infrastructure. All critical infrastructure operators need attack-detection capabilities that provide visibility into both sophisticated and stealthy intrusions.
“Overall, embracing an assume-breach mindset is crucial for rapid recovery from cyberattacks. At the same time, implementing identity forensics and incident response (IFIR) capabilities enhances operational resilience, ensuring that identity systems remain secure against evolving threats. In an environment where regulations like DORA, GDPR, and NIST mandate robust identity protection and swift breach response, IFIR provides a proactive, structured framework that helps minimise business disruptions and safeguard critical infrastructure from compromise.”
This attack draws parallels with recent cyber-attacks that targeted US water utilities across seven states, as reported in our sister magazine ‘Security Journal Americas’.