LONDON: Iranian government-linked hackers reportedly carried out a cyberattack on a British power plant last month, forcing the facility to shut down for four days, according to a report by The Telegraph.
The incident is being described as potentially the first known case in which hackers linked to the Iranian government successfully disrupted and completely shut down a power-generation facility in the United Kingdom.
According to the report, the affected plant remained offline for four days while staff worked continuously to restore its operations. British authorities have reportedly declined to identify the facility, citing security concerns.
Officials have also avoided publicly confirming whether the incident was directly linked to Iran. However, security sources reportedly believe that the attackers were associated with Iranian state interests.
The reported attack occurred around the same time as a series of cyber incidents targeting water infrastructure in the United States. Those attacks affected water-related systems across several states and reportedly raised concerns within the U.S. government over the vulnerability of critical infrastructure to foreign cyber operations.
The British facility affected by the incident is believed to have been relatively small. As a result, its shutdown reportedly did not have a significant impact on the country’s wider electricity generation or transmission network.
Nevertheless, cybersecurity experts regard the incident as significant because of the nature of the disruption. While governments and security agencies have repeatedly warned that hostile states could target critical infrastructure, successful attempts to completely shut down a British power plant have reportedly been extremely rare.
The incident has therefore raised fresh concerns about the vulnerability of Britain’s energy infrastructure to sophisticated cyberattacks.
According to The Telegraph, experts believe the objective may have been less about causing widespread disruption and more about demonstrating capability. The attackers may have wanted to show that Iranian-linked cyber groups could penetrate sensitive British systems and potentially disrupt important infrastructure.
Security specialists have repeatedly warned that energy facilities are particularly attractive targets because their industrial control systems can be connected to computer networks and, in some cases, exposed to sophisticated cyber threats.
A successful attack against such systems can have consequences beyond the targeted facility. Although the reported incident did not cause a wider electricity crisis, prolonged disruption at a larger plant or at multiple facilities could potentially create serious operational challenges.
The reported involvement of hackers linked to Iran is also significant in the context of growing international tensions surrounding Iranian cyber activity. Western governments have previously accused Iranian state-linked groups of targeting government agencies, businesses and critical infrastructure.
Cybersecurity researchers have increasingly documented attempts by state-sponsored hacking groups to gain access to operational technology networks. Such networks control physical processes at facilities including power stations, water-treatment plants and industrial sites.
Experts say that gaining access to these systems does not necessarily mean attackers can immediately cause physical damage. However, demonstrating the ability to access and disrupt operational systems can itself serve as a warning and potentially provide attackers with options for future operations.
British security officials are therefore understood to be treating the incident seriously, even though the affected plant was relatively small and the wider electricity network was not disrupted.
The reported four-day shutdown highlights the potential consequences of cyberattacks against critical infrastructure. It also underlines the difficulty of defending industrial facilities where computer systems directly interact with physical machinery.
Authorities have not publicly disclosed the identity of the plant, the precise method used by the attackers or the full extent of the systems that were compromised.
The incident is expected to fuel further debate in Britain over cybersecurity standards for energy companies and other critical infrastructure operators.
While the attack reportedly did not threaten Britain’s overall electricity supply, experts believe it could represent an important warning: hostile cyber groups may increasingly seek to demonstrate that they can move beyond stealing information and actually disrupt physical infrastructure.
If confirmed, the incident would mark a notable escalation in the cyber threat posed by Iranian-linked groups and could prompt British authorities and energy operators to strengthen protections around industrial control systems and other critical infrastructure.



