Iranian-affiliated hackers successfully forced a power plant in the United Kingdom to go offline, marking what is believed to be the first time such a facility has been shut down by these actors in the country. The incident, which occurred in July but has only recently surfaced, involved a small-scale facility and did not disrupt the broader national power supply.
The breach involved the targeting of programmable logic controllers (PLCs), which serve as the automated brains for critical industrial systems. These devices are ubiquitous across global infrastructure, managing everything from energy grids and water systems to hospital power backups, chemical plant pressure levels, and even traffic light synchronization. Experts estimate that between 12 million and 70 million of these units are currently in operation worldwide, with many older models dating back to the late 1960s and lacking modern cybersecurity protections.
The U.K.’s National Cyber Security Centre was contacted regarding the incident but declined to confirm or deny the occurrence. The attack resulted in a four-day outage as facility staff worked to regain control of the systems. While no group has claimed responsibility, security analysts suggest the operation may have served as a proof-of-concept test, allowing hackers to navigate vulnerable systems before potentially targeting more sensitive, high-value infrastructure.
This event coincided with a series of attacks on water systems across a dozen U.S. states, including Minnesota, Georgia, South Dakota, and New Jersey, where operators were locked out, leading to flooding and pressure loss. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has noted that attackers are often utilizing rudimentary methods, such as scanning for devices exposed on the public internet and exploiting default credentials that remain unchanged by operators.
Securing these industrial components has proven difficult, as the responsibility typically falls on small utility providers with limited cybersecurity resources. A 2024 scan revealed that thousands of PLCs remain exposed and searchable on the open internet, despite the fact that many were never designed with security as a primary requirement.
The U.K. has been on high alert regarding Iranian cyber activity for years, having previously condemned the nation for a 2022 attack that crippled government services in Albania. These warnings have intensified significantly throughout the current year, fueled by regional geopolitical tensions.
Dr. Richard Horne, head of the National Cyber Security Centre, recently disclosed that the agency managed over 200 cyberattacks against critical British infrastructure over the past year. Approximately 75% of those incidents were linked to hostile states, including Russia, China, and Iran. The report also notes that computers called “programmable logic controllers” were targeted, according to U.S, in both attacks. officials and people familiar with the matter in the U.K. The report also notes that in chemical plants to control temperature and pressure to avoid explosions and in elevators and trains to control speed, but they are also used ubiquitously in hospitals to help supply power in blackouts. The report also notes that from roughly 12 million to more than 70 million, according to market research firms, industry estimates on how many PLCs are in use worldwide vary widely. The report also notes that the strategy is more akin to looking for unlocked doors versus high-tech hacking. The report also notes that triggered by the U.S.-Israel war against Iran and the killing of Supreme Leader Ayatollah Ali Khamenei, but the warnings sharply intensified early this year.
Source: CBS News












































































