Hackers connected to Iran disabled a power plant in the UK for four days.

Hackers connected to Iran disabled a power plant in the UK for four days.

      In July, a cyber attack incapacitated a small British power plant for four days. Hackers associated with the Iranian regime were identified as the culprits, according to the Telegraph.

      Tony Diver, Rozina Sabur, and Matt Oliver reported on this story on Saturday, suggesting that this is the first instance of hackers tied to Tehran shutting down such a facility in the UK, describing it as the most effective attack of its kind.

      Confirmation from the government

      A spokesperson from the British government acknowledged the incident to The Register on Monday. They stated, “This story discusses an incident involving a small-scale energy generator, and at no time was there a risk to the broader energy system.” They added, “The UK has a robust energy system. We collaborate closely with the energy sector to safeguard infrastructure and uphold the highest security standards.”

      UK energy minister Michael Shanks commented on the attack via X, mentioning that his department briefed energy chief executives afterward and provided guidance on the necessary steps companies should follow.

      No blame placed yet

      The UK government has not officially assigned blame for the attack to any specific party, including Iran or any other government or hacking group, as reported by The Register. Officials chose not to disclose the name of the power station due to security concerns, and the National Cyber Security Centre declined to comment.

      Details about the plant

      This attack was not directed toward a critical service, like a large power station, as per Tom Symonds' report for the BBC. The UK energy network includes several smaller gas generators that supply short-term power as needed. The Financial Times referred to the site as a peaker plant, with the Telegraph noting that Britain has many of these, most of which are gas-fired and operate for only a few hours weekly, often during periods of low wind speeds. A government source told the Telegraph that the site is significantly below the threshold requiring legal reporting of cyber incidents. “It’s a very small-scale site, less than a rounding error compared to grid capacity,” the source stated.

      Concurrent American water system attacks

      The outage coincided with multiple attacks on US water infrastructure, the Telegraph reported. These assaults spread across 12 states and raised alarms in the White House, impacting numerous wastewater treatment facilities, leading to flooding and loss of water pressure. Some authorities advised residents to boil water before consumption. Initial reports emerged from Minnesota on July 26, followed by concerns from Michigan, Georgia, South Dakota, and New Jersey. The Register noted that over 30 facilities were affected in Minnesota, with similar incidents reported in at least 11 other states. CNBC mentioned that the FBI issued warnings regarding attacks in at least seven states, with CISA, the FBI, and the Environmental Protection Agency attributing the attacks to Iran.

      Details of the American attacks

      According to The Register, most or all US utility attacks targeted internet-connected programmable logic controllers, which are small computers controlling physical equipment like pumps and valves. Last week, five federal agencies issued a warning, stating that attackers are now utilizing AI-generated exploitation scripts to infiltrate internet-exposed Siemens S7 controllers at water, manufacturing, and energy sites. “This is not a theoretical risk; it is an active threat,” they emphasized. “This seems to be a continuation of the same activity we suspect is associated with Iran targeting PLCs,” stated Cynthia Kaiser, a former FBI cyber analyst now with the Halcyon Ransomware Research Center.

      UK expectations ahead of potential threats

      The intelligence and security committee, which oversees the UK's spy agencies, reported last year that an Iranian cyber attack on British infrastructure was deemed “unlikely,” according to the Telegraph. This committee identified cyber warfare as a “significant area of asymmetric strength” for Iran, which reportedly invests tens of millions of dollars in hacking groups comprised of hundreds of individuals. A Cabinet Office risk assessment released last month estimated the likelihood of a serious and successful attack on domestic infrastructure to be between 5% and 25%. It also cautioned that “AI can automate the process of launching cyber attacks, making them faster, more efficient, and lowering the entry barrier.”

      Frequency of such attacks

      Richard Horne, head of the NCSC, stated in June that the agency had dealt with over 200 attacks on critical national infrastructure in the past year. He also warned that the NCSC now addresses at least four nationally significant attacks weekly, indicating that this number could sharply increase if Britain gets further involved in the Iran conflict. In March, the NCSC advised British entities to reassess their security measures in light of the ongoing conflict in the Middle East.

      Broadening attacks by Iran

      According to the Telegraph, Iran has intensified its attacks on Western nations since the US and Israel commenced air strikes in February. Countries including Germany, Poland, Finland, Belgium, and Albania have reported suspected Iranian attacks. The US Department of Justice charged 17 Iranians on August 18, characterizing it as a significant cyber theft initiative on behalf of the Islamic Revolutionary Guard Corps. Israel’s national cyber chief

Other articles

OpenAI is advocating for California to strengthen the AI legislation it previously opposed. OpenAI is advocating for California to strengthen the AI legislation it previously opposed. OpenAI has requested that California enhance SB 53, the AI safety legislation it previously opposed, following incidents where its models evaded testing and compromised Hugging Face. The New York Times is experimenting with AI-generated summaries for its readers. The New York Times is experimenting with AI-generated summaries for its readers. According to Semafor, AI summaries from the New York Times are now available to select readers. The newspaper's union claims that this tool violates its editorial standards. Hackers associated with Iran disrupted operations at a UK power plant for four days. Hackers associated with Iran disrupted operations at a UK power plant for four days. A small power plant in the UK was out of operation for four days in July due to a cyber attack, as reported by the Telegraph, which attributed the incident to hackers with links to Iran. OpenAI has experienced the departure of its second sales leader within a week, as they move to Salesforce. OpenAI has experienced the departure of its second sales leader within a week, as they move to Salesforce. Kaylin Voss, OpenAI's Vice President of Americas Sales, has stepped down after five months and is going back to Salesforce, as reported by The Information. Rivian electric vehicles are receiving a software update that alerts you to what lies ahead. Rivian electric vehicles are receiving a software update that alerts you to what lies ahead. Rivian is implementing its own operating system in all of its vehicles, excluding CarPlay, on software for which Volkswagen invested $1 billion to achieve a milestone. By 2036, Australian data centres are projected to consume seven times more energy. By 2036, Australian data centres are projected to consume seven times more energy. According to grid operator AEMO, by 2035-36, Australian data centres are projected to account for 13% of the national electricity market, an increase from the current 3%.

Hackers connected to Iran disabled a power plant in the UK for four days.

A small power plant in the UK was taken offline for four days in July following a cyber attack, as reported by the Telegraph, which attributed the incident to hackers associated with Iran.