Hackers linked to Iran have been blamed for a cyberattack that forced a small British power facility to shut down for four days, raising concerns over the vulnerability of the UK’s energy infrastructure.
The attack took place in July and targeted a small gas-fired “peaker” plant, according to reports. The owner and location of the facility have not been disclosed.
The plant had a capacity of about 15 megawatts and was connected to a local electricity distribution network. It was not considered critical to the national grid.
The UK has around 300 similar peaker plants, with a combined capacity of between 4GW and 7GW. They are designed to provide additional electricity when demand increases and are typically operated remotely using programmable logic controllers.
The incident was reported to the National Cyber Security Centre (NCSC), part of GCHQ. No power cuts were reported, and the attack did not threaten the wider electricity system.
The British government has confirmed that a cyber incident affected a small-scale generator but has not publicly attributed the attack to Iran.
Energy minister Michael Shanks said: “To be clear: there was no threat to the wider grid and nobody lost power.”
He added: “The generator in question is tiny especially compared to what most of us would class as a ‘power plant/station’.”
A government source told The Sunday Telegraph: “We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near. It’s a very small-scale site, less than a rounding error compared to grid capacity.”
The incident has prompted concerns over Iran’s ability and willingness to target British infrastructure.
A former security official said: “This is a clear warning shot from the Iranian state. They’ve already disrupted global oil supplies. Now they’re threatening to attack critical national infrastructure in the UK.”
Alicia Kearns, the shadow security minister, said the attack “must not be shrugged off”.
She said: “It should be the shot across the bow needed to wake-up the government.
“Our critical infrastructure was built for reliability, not for an age of contest. It is lightly defended and in many cases laid bare on Google Maps for any hostile actor to identify.
“Take out one asset or electricity pylon and a few hundred homes go dark. Take out the wrong node and it’s thousands, for weeks. At that point you are no longer managing an outage, you are managing public confidence in the state’s ability to keep the lights on.
“Frontier AI has collapsed the cost of finding and exploiting those weaknesses. The capability that used to require a state now requires little more than a laptop.
“We spend billions deterring threats that arrive by submarine and ballistic missile, but the government is insufficiently focused on the vulnerabilities of the everyday infrastructure we rely on. We need an immediate strategic review of where Britain is genuinely vulnerable, and government action to defend us, now.”
Lord Walney, the government’s former adviser on political violence, said: “This underlines that Iran is conducting a hybrid war against the UK with significant impact on British citizens. The UK government likes to emphasise it did not join the recent military action against Iran but it is clear that the Iranian regime is trying to harm the country whether or not we stand on the sidelines.
“Ministers must urgently step up a co-ordinated strategy that increases resilience against Iranian activity at all levels.”
The attack comes amid warnings over increasing state-linked cyber activity against Britain.
NCSC chief executive Richard Horne said this month that hostile states were linked to around three-quarters of cyber incidents affecting the UK’s critical systems over the previous year.
The NCSC has identified Russia, China and Iran among the states posing cyber threats to the UK.
The Department for Energy Security and Net Zero briefed energy company executives following the latest incident. It also wrote directly to companies with advice on protecting their systems.
The government said: “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.
“This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.”
The incident comes as the government moves to strengthen cyber security requirements for essential services.
The Cyber Security and Resilience Bill would expand the range of cyber incidents that regulated organisations must report.
Under the proposed rules, organisations would have to provide an initial notification of a significant incident within 24 hours and a full report within 72 hours. The NCSC would be informed at the same time as the relevant regulator.
The legislation would also expand the organisations covered by the UK’s cyber security regime and strengthen regulators’ enforcement powers.
