Hackers believed to be linked to the Iranian regime shut down a small gas peaking power plant in the UK for four days in early July 2026. The plant has a capacity of approximately 15 megawatts and was taken offline through a cyberattack targeting its programmable logic controllers (PLCs), which are known vulnerabilities hackers often exploit [1, 2, 3, 4, 5].

The shutdown caused no significant disruption to the UK’s national electricity grid or the broader power system. Michael Shanks, UK Energy Minister, said, "The generator in question is tiny especially compared to what most of us would class as a ‘power plant/station’. That being said, the generator and govt took the incident seriously" [2].

The targeted plant is one of about 300 small peaking plants across the UK, which together provide between 4 and 7 gigawatts of capacity. Many of these plants operate unmanned and rely on PLCs vulnerable to cyberattacks, making them potential targets for hostile actors [1, 3]. As one industry insider noted, "Due to the very small scale of this plant, there was no formal cybersecurity protection mechanism. PLCs are a well-known security weakness exploited by hackers" [1].

The UK government’s National Cyber Security Centre (NCSC) and the Department for Energy Security and Net Zero briefed energy company leaders on August 23 and issued guidance to strengthen defenses following the attack [1, 3]. Energy UK expressed concern over the rising threat level, saying, "The increased threat level is worrying. While the government's involvement is welcome, we clearly face challenges to ensure UK infrastructure meets 21st century requirements" [1].

This incident marks the first confirmed cyberattack on the UK’s energy infrastructure attributed to Iranian-linked hackers [2, 5]. Around the same time, similar attacks attributed to the same group affected water infrastructure in 12 US states [2, 4, 5].

Cyberattacks on critical infrastructure are rising globally. Taiwan’s power system, for example, faces about 30,000 daily attempts to breach its networks, increasingly from China-linked hackers [5].

The UK government’s latest response aims to harden defenses of small power plants vulnerable to attack, as these sites play a critical role in balancing the grid during peak demand. Further updates and security measures from the NCSC are expected as investigations continue [1, 3].