🕒 Created · Updated

Iranian-linked hackers successfully took a British power plant offline for four days in a significant cyberattack.

Iranian-linked hackers successfully took a British power plant offline for four days in July, marking the first time such a facility in the United Kingdom was shut down by Iranian cyber activity. While the facility was small-scale and did not impact the overall national power supply, the attack serves as a demonstration of Iranian capabilities and intent. The breach targeted programmable logic controllers, which are the brains of automated industrial systems used in energy, water, and manufacturing. Simultaneously, Iranian-linked actors are believed to have targeted water systems across 12 U.S. states, including New Jersey, Minnesota, and Georgia. These attacks highlight a growing shift toward targeting physical infrastructure rather than just data. Security experts note that the methods used are often simple, such as exploiting default passwords on exposed devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that responsibility for securing these systems often falls on individual operators. Experts suggest these smaller incidents may be proof-of-concept attempts to test systems before targeting more sensitive, high-value targets in the future.

Sources