Cyberattack shuts down UK power plant for four days - Expert Comments

A cyberattack forced a British power plant offline for four days while staff worked to restore operations, in what is believed to be the first cyberattack to successfully shut down a UK power generation facility.

Officials have not identified the plant for security reasons but said it was a small generator and the outage did not affect the wider UK power supply. The incident was reported to the UK’s National Cyber Security Centre (NCSC).

The incident comes alongside attacks on dozens of U.S. water and wastewater facilities across 12 states, which caused operational disruptions including flooding and loss of water pressure, with some communities instructed to boil their water.

The NCSC has separately reported handling more than 200 attacks on UK critical national infrastructure during the past year.

Experts from Black Hills Information Security, Inc., Suzu Labs, Xcape, Inc. and BreachLock provide comments on the matter.

John Strand, Owner, Black Hills Information Security, Inc.:

“This particular breach scares me, not necessarily because it happened in the United Kingdom, but because of how much further behind the United States power grid is compared to Europe. Modernization of the U.S. power grid has been painfully slow for a number of reasons, including legislative capture and the basic economics of how utilities make money. They make money from generating and selling power. They don’t necessarily make money from updating aging infrastructure.

“Then there’s the interconnected nature of the U.S. power grid, with Texas being the notable exception. A relatively small problem at a substation can create ripple effects across multiple areas of the grid. That’s what makes this such a serious wake-up call. When you combine that interconnectedness with the incredibly slow pace of infrastructure modernization, especially across the power grid, I’m very concerned. I think an attack like this could potentially have a far greater impact in the United States than what we’re seeing in Europe.”

Denis Calderone, CTO, Suzu Labs:

“What has our attention here is not the size of the generator. A savvy attacker isn’t choosing targets based on grid capacity. They’re probing for the weakest point in the armor, and a facility small enough to fall below mandatory cyber reporting thresholds is exactly the kind of target that’s likely under-defended and overlooked.

“Two weeks ago in Poland, a compromised wind farm became a direct bridge into a completely separate heating plant’s SCADA system through a shared cellular network. Different threat actor, different country, same playbook: find the overlooked facility, use it as a stepping stone. We’ve been tracking Iran-linked operations against Western critical infrastructure since April, and the pattern keeps escalating. PLCs targeted for operational disruption. Gas station fuel monitoring systems. Water systems across 12 US states in a single month. Five agencies flagged AI-generated tools targeting Siemens PLCs four days ago. And now a UK power facility goes dark for four days.

“The victim became the victim because of poor hygiene. The advice here is the same as it ever was, because the exposure hasn’t changed. Take controllers off the internet. Change default credentials. Inventory every communication path, especially the integrator-installed remote access links and the backup channels that never made it onto a network diagram. But critical infrastructure operators need to be proactively hunting for these weaknesses and prioritizing remediation before an adversary does the discovery for them. The smaller satellite sites are often the ones that fall under the radar during security reviews, so make sure you look at everything. Small and overlooked is exactly what made this target attractive.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“There is a real and growing threat to critical infrastructure, however the way we talk about these incidents matters.

“If this was genuinely a historic cyber-induced shutdown of a British power generator, then operators need to know what made it possible. Was a PLC directly exposed to the Internet? Was remote access compromised? Did attackers manipulate the physical process, or did operators shut the plant down defensively after an IT compromise? What control would have broken the attack chain?

“Don’t tell me this was historic and then redact the history.

“We can protect the identity of the victim and sensitive operational details while still publishing a sanitized technical account. CERT Polska has shown what responsible disclosure can look like: explain the attack path, identify the class of failure, and give other operators something they can actually use to defend themselves.

“The same caution applies to attribution. “Iran-linked” is not the same thing as proving that the Iranian government directed the attack. We should distinguish what happened to the plant, who conducted the intrusion, and by which nation state it was instructed. Attribution in cyberspace is an analytical conclusion, not something you read off the source IP address.

“The larger problem is that too many cyber incidents and near misses disappear into non-disclosure or tightly held incident reports. One operator learns an expensive lesson while thousands of others are left to learn it again. The point of incident reporting should not simply be counting attacks. It should be making the next attack harder.

“We keep sweeping these incidents and near misses under the rug when we should be dragging them into the light and learning from them.

“If joint cybersecurity advisories can say what went wrong in Minnesota without handing attackers a blueprint, we should be able to tell operators what class of failure took a British peaking plant offline for four days.”

Seemant Sehgal, Founder & CEO, BreachLock:

"OT in power plants and water treatment facilities wasn’t designed with adversarial persistence in mind. The visible coordination across a UK facility and dozens of US water systems in the same window indicates that these environments are being mapped and tested well before the disruptive payload arrives.

“The teams running these facilities need to know which of their OT assets are reachable, how an attacker would move from IT into operational systems, and where their recovery dependencies sit, because it’s already too late to be asking those questions by the time the outage clock starts."

Articles similaires

Opinion

10 September 2026

Cyberattack encrypts German utility’s IT systems serving critical infrastructure – experts weigh in

A cyberattack that began September 1st has encrypted the central IT systems of Stadtwerke (…)

Opinion

9 September 2026

Are AI agents the next insider threat?

In a new interview published in Axios, Bugcrowd CEO Dave Gerry said that AI agents aren’t just (…)

Opinion

4 September 2026

CISA cuts critical infrastructure security services, concerns grow over the shrinking agency - Expert Comments

CISA is ending six free cybersecurity assessment programs used by critical infrastructure (…)