Iran-linked cyberattack briefly shutters UK power plant

A suspected Iran-linked cyberattack forced a small UK power generator offline for four days in July, an incident officials say did not threaten the wider grid but highlights mounting risks to industrial control systems that underpin critical infrastructure.[1][5][6]

The shutdown was first reported by The Telegraph, which disclosed that hackers believed to be affiliated with the Iranian regime successfully took a British power plant offline in what security officials described as an unprecedented attack of its kind in the country.[1][10][15] The UK Department for Energy Security and Net Zero (DESNZ) later confirmed that the incident affected a “small-scale energy generator” and stressed that “at no point was there a risk to the wider energy system,” while the National Cyber Security Centre was notified and involved in the response.[2][5][6] Government spokespeople have not identified the facility or its operator, and the UK has stopped short of formally attributing the intrusion to Iran or any specific threat group, despite multiple reports citing unnamed officials who link the activity to Tehran.[2][4][5]

The attack on the British generator came weeks after a coordinated campaign against US water utilities that similarly targeted operational technology rather than traditional IT systems.[7][13] On July 26 and 27, more than 30 community water systems across Minnesota experienced disruptions following what state officials described as a “coordinated cyberattack” aimed at industrial control equipment, with at least one treatment plant taken fully offline.[7][12][13] Security researchers at Tenable and other firms say the activity bears the hallmarks of CyberAv3ngers, an Iran-linked faux hacktivist group formally attributed to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command and sanctioned by the US Treasury in 2024 for systematic campaigns against US water infrastructure, though no US agency has yet issued a formal attribution for the Minnesota incidents.[7][12][13]

Investigators believe the Minnesota campaign relied on weaknesses in internet-exposed programmable logic controllers (PLCs), including exploitation of CVE-2021-22681, a critical authentication bypass in Rockwell Automation’s Logix controller family that allows remote compromise when default credentials or weak network segmentation are in place.[7][12] Unitronics Vision Series PLCs configured with default passwords and open remote access also featured in some intrusions, giving attackers direct control over pumps, valves, and chemical dosing without needing to breach corporate IT networks.[7][12] These techniques mirror a broader Iranian focus on OT targets, where low-cost, widely deployed PLCs present a soft underbelly for adversaries seeking physical disruption with comparatively modest technical investment.[12][13]

Concerns around the UK power-plant hack have intensified in light of a recent joint cybersecurity advisory that confirms threat actors are now using AI-generated code to attack Siemens S7 Series PLCs deployed across water treatment, energy, manufacturing, and other industrial environments.[8][9][11] Advisory AA26-231A—issued by the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency—warns that adversaries are leveraging internet-scanning services such as Censys and ZoomEye to identify Siemens S7 controllers with port 102 exposed, then feeding that data into AI tools that produce functional Python exploitation scripts built on the open-source snap7 and python-snap7 libraries.[8][11][14] Those scripts are disguised as legitimate OT monitoring software, giving attackers read and write access to PLC memory, configuration data, and ladder logic without triggering traditional malware detection, prompting US agencies to describe the situation as “not a theoretical risk – it is an active threat.”[8][11][14]

OT security specialists argue that the British generator shutdown, the Minnesota water disruptions, and the emerging AI-assisted Siemens S7 campaigns point to a sustained effort by Iran-affiliated actors to probe and degrade industrial systems that support everyday life.[7][12][13] Researchers tracking CyberAv3ngers and related activity say Iranian operators are deliberately targeting PLCs and other field devices because they directly control essential health, safety, and critical infrastructure functions, from potable water delivery to electricity generation, while often running on legacy hardware with minimal monitoring and poor password hygiene.[7][12][13] The lack of public technical detail around the UK incident makes it impossible to say whether the same tradecraft was used there, but the timing and apparent focus on a small generator rather than a large grid operator fit a pattern of testing and escalation rather than a single, isolated event.[1][5][10]

Defenders are being urged to respond by treating OT networks with the same rigor traditionally reserved for high-value IT environments, beginning with eliminating unnecessary internet exposure for PLCs and enforcing strong, unique credentials and multifactor authentication wherever possible.[8][9][11] The US joint advisory recommends segmenting industrial control systems from business networks, disabling unused services like open S7comm ports, and continuously monitoring for unusual connections from external IP ranges or newly introduced tools that claim to be monitoring software but exhibit direct read-write access to PLC logic.[8][11][14] UK officials, meanwhile, say they have briefed energy CEOs and shared additional security guidance across the power sector following the generator shutdown, positioning the episode as a warning shot that resilience depends not only on the strength of the national grid but on the cyber hygiene of every small operator connected to it.[2][5][6]

References

  1. Iranian hackers shut down UK power plant – The Telegraph
  2. Iran-linked hackers behind cyber attack that shut down power … – BBC
  3. Iranian cyberattack shuts down British power plant for four …
  4. Iran-linked hackers blamed for cyber-attack that shut down …
  5. Iranian hackers force UK power plant offline for days
  6. CyberAv3ngers Hits 30+ Minnesota Water Utilities: CISA AA26 …
  7. [PDF] Defending Against an Active Threat to Siemens S7 Series PLCs
  8. [PDF] Defending Against an Active Threat to Siemens S7 Series PLCs
  9. The Telegraph: Iranian hackers disrupt British power station in unprecedented cyberattack
  10. Feds Confirm AI Is Writing Exploits for Siemens PLCs Used in Water …
  11. Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems
  12. Iran-linked CyberAv3ngers suspected in attacks on …
  13. #criticalinfrastructure #ics #cybersecurity #cisa | Gerald …
  14. The Telegraph

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply