Iran-linked hackers halted a small UK power plant for four days
The outage did not threaten Britain’s electricity supply, but officials saw it as a warning about vulnerabilities in critical infrastructure.
As reported by pravda.com.ua.
Hackers linked to the Iranian regime brought a small power plant in the United Kingdom to a standstill for four days in a cyberattack. This may be the first known case of Iranian cybercriminals disabling a facility of this kind in the UK.
British officials are withholding the name of the power plant for security reasons. It is only known that specialists spent four days trying to restore its operations.
The facility had relatively low capacity, so its temporary shutdown did not affect the UK’s overall energy supply or electricity generation.
The Aim of the Attack on the Power Plant
British intelligence agencies believe the cyberattack was unlikely to have been intended to harm civilians. Its main purpose was probably to demonstrate the ability of hackers linked to the Islamic Revolutionary Guard Corps to infiltrate British systems and shut down critical infrastructure facilities.
The incident was reported to the National Cyber Security Centre (NCSC), which is part of the Government Communications Headquarters (GCHQ). The British government subsequently briefed energy company executives and provided them with recommendations on strengthening network security.
The country’s energy system is highly resilient, and the authorities continue to work closely with the sector to maintain security.
– a British government spokesperson
A government representative explained that major electricity producers are required to report cyber activity to the authorities, but the targeted facility did not meet these criteria because of its small scale.
We have criteria in place under which key electricity producers are legally required to report cyber activity to us, but this facility does not come close to meeting them. It is a very small-scale facility, accounting for less than a statistical error compared with the network’s overall capacity.
Cyberattacks on Water Facilities in the US
Around the same time, a series of cyberattacks on water supply facilities was recorded across 12 US states. The attackers targeted dozens of treatment plants, causing flooding, drops in water pressure, and recommendations from local authorities to boil water before drinking it.
The first breaches were detected in Minnesota on July 26. Similar incidents were subsequently reported in:
- Michigan;
- Georgia;
- South Dakota;
- New Jersey.
The US government later stated that the attack most likely originated in Tehran.
Iranian Cyber Activity Against Western Countries
Against the backdrop of escalating conflict in the Middle East, Iran has intensified its cyberattacks against Western countries. This became particularly noticeable after the US and Israel began airstrikes in February.
Germany, Poland, Finland, Belgium, and Albania have already fallen victim to Iranian cyber operations. The UK Parliament’s Intelligence and Security Committee has described cyberwarfare as an “important area of asymmetric advantage” for Iran.
The UK Cabinet Office has also warned of new risks associated with artificial intelligence. According to the department, such technologies could automate cyberattacks, making them faster and more effective while lowering the barrier to entry for attackers.
Other news you may find interesting:
- The US Justice Department charged eight Iranian nationals over an alleged hacking campaign targeting government agencies, universities, businesses, and international organizations.
- A series of cyberattacks disrupted water facilities across several US states, while investigators examined possible Iranian involvement and widespread exposure of internet-connected control systems.
- Sweden’s civil defense minister warns GRU-linked groups have shifted from DoS to destructive cyberattacks targeting energy and critical infrastructure across Scandinavia and Europe.
