British Power Plants Hit by Iranian Cyber Attack: Report

Unverified claim: Iranian cyber attack shut UK power plants for four days

Reports have surfaced alleging a major Iranian cyber attack that resulted in the shutdown of British power plants for four days. The news, which emerged from media sources rather than official statements, has sparked serious concern about the cybersecurity of critical UK infrastructure. At the time of writing, UK authorities and the operators of the nation’s power plants have not confirmed the incident, making these claims unverified. However, the potential impact and the nature of the alleged attack warrant close examination and awareness among organisations.

Reported Cyber Attack on British Power Plants

The focus keyword, Iranian cyber attack, appears early in this section as we examine the reported incident. According to a media report, several British power plants were forced offline for four days due to a cyber operation attributed to Iranian threat actors. The attack allegedly targeted the operational technology (OT) controlling the critical infrastructure, disrupting electricity generation and supply across affected regions.

The report, first published on 13 June 2024, does not specify which power stations were impacted or the precise number of facilities affected. It is also unclear whether the disruption led to power outages for end users or if grid stability was maintained through backup or rerouting systems. No energy companies or government agencies have corroborated the claims, and there is no public information from the UK National Cyber Security Centre (NCSC) or the Department for Energy Security and Net Zero regarding such an incident.

Timeline and Claims

  • Alleged attack start: Unspecified, but reported in early June 2024
  • Duration: Four days of disruption claimed
  • Source: Media report citing unnamed sources; no official confirmation
  • Attribution: Blamed on Iranian state-linked cyber actors

The report claims that the attackers used sophisticated techniques to breach networks and disrupt operations, but it provides no technical indicators, malware names or vulnerabilities exploited. It is not stated whether the breach involved phishing, software vulnerabilities, or exploitation of third-party suppliers. The lack of technical detail and official statements means the broader security community has not been able to verify or analyse the alleged tactics, techniques and procedures (TTPs) used.

Who Is Affected by the Alleged Incident?

If the Iranian cyber attack report is accurate, the primary victims would be the operators of the affected British power plants and, by extension, the UK’s energy grid. Disruption of electricity generation could have significant knock-on effects for businesses, public services, and households. However, without confirmation from plant operators or grid authorities, it is not possible to determine the extent of the impact or whether any sensitive data was accessed or exfiltrated during the attack.

The report does not name any specific products, software versions or network components that were compromised. There is no evidence at this stage to suggest that this attack exploited a newly discovered vulnerability or that similar infrastructure elsewhere is currently at risk from the same methods.

Current Exploitation Status

  • No evidence of ongoing exploitation or active attacks sharing the reported characteristics.
  • No indicators of compromise or indicators of attack have been published by authorities.
  • Security researchers and threat intelligence analysts have not corroborated the media claims with technical data.

Given the absence of official confirmation or forensic details, organisations should treat the incident as unverified but remain alert to possible follow-on reporting or advisories from the NCSC or industry partners.

How the Attack Might Have Worked

While the media report offers no technical specifics, attacks on critical infrastructure often involve a blend of social engineering, exploitation of unpatched systems, and lateral movement across operational networks. Iranian threat actors have previously targeted energy infrastructure in other countries using malware, spear-phishing and supply chain vulnerabilities.

Common attack vectors for power plants and similar facilities include:

  • Compromising remote access systems (such as VPNs or RDP)
  • Exploiting outdated or unpatched OT and IT systems
  • Deploying ransomware or destructive malware targeting industrial control systems
  • Leveraging insider threats or compromised credentials

In past incidents, attackers have sought to disrupt plant operations, manipulate control systems or exfiltrate sensitive design and operation data. The alleged four-day outage, if true, would be consistent with a disruptive attack focused on operational disruption rather than data theft alone.

Why This Matters

A successful Iranian cyber attack against British power plants would mark a significant escalation in state-linked cyber operations targeting critical UK infrastructure. Even unconfirmed, such reports highlight ongoing risks to the energy sector and the need for vigilance against sophisticated nation-state threats. The mere possibility of a prolonged outage underscores the importance of robust security and incident response planning across the country’s critical national infrastructure.

What Organisations Should Do Now

While the report remains unverified, organisations operating in the energy sector should:

  • Monitor for official updates from the NCSC or sector authorities
  • Review and update incident response plans for OT and IT environments
  • Ensure ongoing threat intelligence monitoring for new advisories related to Iranian threat actors or power sector targeting

Remaining engaged with trusted sector-specific information sharing groups is essential, especially in the absence of confirmed technical indicators from this event.

Originally reported by Unknown.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call