Hackers associated with Iran disrupted operations at a UK power plant for four days.
A cyber attack incapacitated a small British power plant for four days in July. According to the Telegraph, hackers associated with the Iranian regime were behind the incident. Tony Diver, Rozina Sabur, and Matt Oliver reported this story on Saturday, noting that it is believed to be the first instance of Tehran-linked hackers shutting down such a facility in the UK, labeling it the most successful attack of its type.
What the government has confirmed
On Monday, a spokesperson for the British government verified the event to The Register. "This story pertains to an incident affecting a small-scale energy generator, and there was never a risk to the wider energy system," the spokesperson stated. "The UK has a highly resilient energy system. We collaborate closely with the energy sector to safeguard infrastructure and maintain the highest security standards.”
UK energy minister Michael Shanks commented on the attack via X, indicating that his department briefed energy executives afterward and provided guidance on necessary steps for companies.
The UK has not assigned blame
The government has not officially attributed the attack to anyone, including Iran or any other hacking group, as reported by The Register. Officials abstained from revealing the identity of the power station, citing security concerns, and the National Cyber Security Centre declined to provide comments. The NCSC, which operates under GCHQ and addresses attacks on critical infrastructure, typically does not disclose individual incidents.
The plant was minor
This incident did not target a vital service like a large power station, as noted by Tom Symonds at the BBC. The UK power network includes several smaller gas generators that supply temporary power when necessary. The Financial Times referred to the site as a peaker plant, with the Telegraph reporting that Britain has many of them. Many are gas-powered and operate for only a few hours each week, particularly during low wind conditions. A government source informed the Telegraph that the site is situated well below the threshold at which operators are legally required to report cyber activity, describing it as "a very small-scale site, less than a rounding error compared to grid capacity."
Concurrent attacks on American water systems
The outage occurred simultaneously with a series of cyber attacks on US water infrastructure, according to the Telegraph. These attacks impacted 12 states and raised concerns at the White House. Numerous wastewater treatment plants were affected, resulting in flooding and diminished water pressure. Some authorities advised residents to boil water before consumption. Reports began in Minnesota on July 26, followed by similar incidents in Michigan, Georgia, South Dakota, and New Jersey. The Register stated that more than 30 facilities in Minnesota were affected, with analogous breaches later recorded in at least 11 other states. CNBC reported that the FBI warned of attacks in at least seven states, attributing blame to Iran.
Details of the American attacks
Most or all of the attacks on US utilities involved internet-connected programmable logic controllers, The Register reported. These small computers manage physical equipment such as pumps and valves. Last week, five federal agencies issued a warning stating that attackers now employ AI-generated scripts to exploit vulnerabilities in internet-exposed Siemens S7 controllers across water, manufacturing, and energy sites. "This is not a theoretical risk, it is an active threat," the agencies emphasized. Cynthia Kaiser, a former FBI cyber analyst now with the Halcyon Ransomware Research Center, stated, "This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs."
Expectations for Britain
The intelligence and security committee that oversees Britain's intelligence agencies reported last year that an Iranian cyber attack on British infrastructure was deemed "unlikely," according to the Telegraph. The same committee described cyber warfare as a "significant area of asymmetric strength" for Iran, noting that Tehran invests tens of millions of dollars in hacking groups comprising hundreds of members. A Cabinet Office risk assessment from last month estimated the likelihood of a serious and successful attack on domestic infrastructure to be between 5% and 25%. It also warned that "AI can automate the process of launching cyber attacks, making them faster, more efficient, and lowering the barrier for entry.”
Frequency of incidents
Richard Horne, head of the NCSC, stated in June that the agency managed over 200 attacks on critical national infrastructure in the past year. He also cautioned that the NCSC now deals with at least four nationally significant attacks weekly, a figure that could significantly increase if the UK becomes more involved in the conflict with Iran. In March, the NCSC advised British organizations to reassess their security measures in light of the ongoing situation in the Middle East.
Broader campaign
Iran has intensified attacks on Western nations since the US and Israel initiated airstrikes in February, as reported by the Telegraph. Countries such as Germany, Poland, Finland, Belgium, and Albania have all reported suspected Iranian incursions. On August 18, the US Department of Justice charged 17 Iranians in what was described as a massive cyber theft campaign on behalf of the Islamic Revolutionary Guard Corps. Israel's
Altri articoli
Hackers associated with Iran disrupted operations at a UK power plant for four days.
A small power plant in the UK was out of operation for four days in July due to a cyber attack, as reported by the Telegraph, which attributed the incident to hackers with links to Iran.
