Iran-linked cyberattack knocks UK power generator offline for four days

This digest was compiled by AI from multiple sources — links to the originals are below.
A cyberattack attributed to Iran took a UK power generation plant offline for four days. A UK government spokesperson said the incident affected a small-scale energy generator and posed no risk to the wider energy system. The UK's National Cyber Security Centre issued new guidance on protecting operational technology devices from state-sponsored threats.
Key Facts
- The attack was attributed to Iran, which has increased offensive cyber operations since US and Israeli strikes began in February 2026.
- A UK government spokesperson said the incident affected a small-scale energy generator and at no point posed a risk to the wider energy system.
- The UK's National Cyber Security Centre issued new guidance stating that the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.
- Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the significance is not the size of the facility but that a cyberattack caused four days of real-world operational disruption.
The Attack
A UK power generation plant was taken offline for four days after a cyberattack attributed to Iran. The attack occurred days before the FBI issued a warning over Iranian attempts to hack critical infrastructure in the US. Iran has stepped up offensive cyber warfare efforts since the US and Israel began conducting strikes in February 2026, focusing largely on the US and its allies.
Government Response
A UK government spokesperson said the incident impacted a small-scale energy generator and at no point was there a risk to the wider energy system. The spokesperson added that the UK has a highly resilient energy system and works closely with the energy sector to protect infrastructure and ensure the highest security standards. Following the attack, the UK's National Cyber Security Centre issued new guidance on protecting operational technology devices from state-sponsored threats. The NCSC guidance stated that the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.
Expert Analysis
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said attackers do not care whether an energy operator is large enough to meet a reporting threshold. Patel said the significance is not the size of the facility but that a cyberattack turned into four days of real-world operational disruption. He raised the question of why recovery took four days and whether smaller operators are adequately prepared to contain and recover from such incidents. Patel also noted a potential visibility gap in how smaller operators monitor and respond to cyber threats.