"This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system," a U.K. spokesperson told CNBC.
Four days offline: the immediate facts
In July, a United Kingdom power plant — described by officials as a small-scale generator — was shut down for four days following what has been reported as a potentially Iranian-linked cyberattack. The U.K. spokesperson who spoke to CNBC emphasized that the broader energy system was not at risk and described Britain’s energy grid as "highly resilient."
Why a peaker plant matters: Markus Mueller's technical reading
Markus Mueller, Field CISO at Nozomi Networks, called the incident "a major escalation" beyond the recent cyber campaign targeting U.S. water utilities. Mueller stressed that peaker plants are designed to come online quickly and provide a relatively small amount of power (less than 50 MW or ~25,000 homes) to stabilise the grid. Because they are fast-start facilities with little operational buffer, he said, "things happen fast, there is no buffer, and there can be major impacts."
Mueller outlined a plausible attack path consistent with public reporting: a publicly exposed programmable logic controller (PLC) that had not been secured according to basic best practices. He noted that plants often have multiple control systems — from fuel and turbine control to electric protection relays and environmental monitoring — and the safety and reliability implications depend on which system was affected. If the impacted PLC was an ancillary device (for example one connected to a water well or storage tank) taking it offline could still force a shutdown; if the main control system for turbines or boilers were accessed, the safety risk would be greater.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageReported tactics: exposed PLCs, AI scripts, and default credentials
Mueller described the attack method being associated with recent water utility intrusions in the United States: threat actors scanning the internet for exposed PLCs using AI-generated scripts, then logging into those PLCs with default credentials and taking them offline by resetting programming, changing passwords, and modifying IP addresses to make devices inaccessible. He suggested a timely, detailed technical report from the U.K.'s National Cyber Security Centre (NCSC) would be valuable — comparing it to CERT Polska's public analysis of the Poland Energy attacks in December 2025 as an example defenders might learn from.
Attribution, timing, and international signals
While the U.K. spokesperson declined to publicly attribute the attack, the source material notes that "many suspect Iranian involvement" and that some reports attribute the activity to a unit described as the IRGC hacking group known as CyberAv3ngers. The incident occurred around the same time U.S. authorities issued warnings about malicious actors targeting water and wastewater utilities, a temporal coincidence that has informed reporting and vendor commentary.
How technologists, policymakers, and utilities are likely to react
- Technologists and security teams: Expect an operational focus on exposed industrial devices — especially PLCs — and basic hygiene such as removing default credentials and closing public-facing management interfaces. Mueller recommended that defenders leverage resources from organisations like the NCSC and security vendors to harden controls.
- Policymakers and regulators: The U.K.'s Department of Energy Security has stated it intends to update cybersecurity regulations. Regulators will likely prioritise rules and guidance aimed at small-scale generators and other grid-adjacent assets that can be overlooked in national continuity planning.
- Utilities and communities: Operators of peaker plants and other fast-start facilities will face renewed scrutiny of their segmentation and backup procedures. Mueller urged utilities and communities to "get their house in order," noting that both government bodies and vendors can provide assistance.
From the account available, the central technical unknown remains which system was impacted — an ancillary PLC that forced a safe shutdown, or direct access to main turbine or boiler controls with more serious safety implications. The event marks, in Mueller's words, "a major escalation" in the types of industrial targets being exploited and has prompted a regulatory response from the Department of Energy Security. A clear, technical disclosure from NCSC could narrow the knowledge gap and offer actionable steps for operators; until then, defenders will be left to harden exposed devices and await formal guidance.
Source: securitymagazine.com — Iranian Cyberattack Shuts Down UK Power Generator




