Home Breaking NewsIran strikes Britain from the shadows as hackers shut down power plant

Iran strikes Britain from the shadows as hackers shut down power plant

by LLB staff reporter
23rd Aug 26 12:18 pm

Iran-linked hackers have penetrated and shut down a British power plant for four days in what officials and security experts regard as an unprecedented attack on the country’s energy infrastructure.

The incident, first revealed by The Telegraph, is believed to be the first known occasion on which hackers affiliated with Tehran have successfully disabled a power facility in Britain.

While the affected plant was small and its shutdown had no discernible effect on the national grid, the breach has exposed a more troubling vulnerability: hostile state-backed hackers were able to penetrate a British energy system and keep it offline for days.

Officials have refused to identify the facility, citing security concerns. Staff spent four days restoring operations and bringing compromised systems back online.

The attack is not thought to have been intended to cause widespread disruption or civilian casualties. Its significance may instead have been demonstrative — showing that cyber units associated with Iran’s Islamic Revolutionary Guard Corps can gain access to sensitive British infrastructure and, at least temporarily, take control of it.

That distinction is becoming increasingly difficult for western governments to dismiss.

The British attack coincided with a wave of cyber incidents targeting US water infrastructure, with breaches reported across 12 states and raising concerns at the White House.

Those attacks struck dozens of wastewater treatment facilities, causing flooding, reduced water pressure and boil-water advisories in some communities.

Minnesota recorded its first incident on July 26, followed by similar breaches in Michigan, Georgia, South Dakota and New Jersey.

The FBI initially attributed the attacks to “malicious cyber actors”, while US government sources subsequently told media that the campaign was believed to have originated in Tehran.

The parallel incidents suggest a broader pattern of Iranian cyber activity against Western infrastructure at a time of heightened geopolitical tension.

Iran has sharply expanded its cyber operations against Western states since the escalation of the Middle East conflict in 2023, and particularly since the launch of “Operation Epic Fury” earlier this year.

Suspected Iranian attacks have also been reported in Germany, Poland, Finland, Belgium and Albania, although Israel and other Middle Eastern countries remain the principal targets.

Britain’s vulnerability is of particular concern because much of the country’s energy system relies on a large number of smaller generators connected to the national grid.

The affected facility is understood to have been one of dozens of relatively small-scale plants, many of them gas-fired, that operate intermittently rather than providing a continuous share of national generation.

A four-day outage at such a plant would therefore have been little more than a rounding error in national power capacity.

But the fact that the facility could be remotely disabled presents a different kind of risk.

The Government responded by briefing power-company chief executives and issuing guidance to businesses. The incident was also reported to the National Cyber Security Centre, the public-facing arm of GCHQ.

Security officials have repeatedly warned that hostile states are exploiting cyber capabilities as a relatively cheap means of testing Western defences.

The Intelligence and Security Committee, which scrutinises Britain’s intelligence agencies, judged last year that an Iranian cyberattack on UK infrastructure was “unlikely”.

It nevertheless described cyber warfare as a “significant area of asymmetric strength” for Tehran.

Iran invests tens of millions of dollars in cyber capabilities and has hundreds of operatives working within its hacking apparatus, according to the committee.

The scale of the threat is growing faster than the public’s awareness of it.

In June, NCSC chief executive Richard Horne said the agency had dealt with more than 200 attacks on critical national infrastructure during the preceding year.

A Cabinet Office risk assessment published last month put the likelihood of a serious cyberattack against domestic infrastructure at between 5 and 25 per cent.

It also warned that artificial intelligence could materially increase the danger, noting that “AI can automate the process of launching cyber-attacks, making them faster, more efficient and lower the barrier for entry.”

The Government has sought to play down the immediate significance of the latest incident.

A Government source said: “We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near.

“It’s a very small scale site, less than a rounding error compared to grid capacity.”

A Government spokesman added: “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.

“This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.”

That reassurance may be accurate in terms of electricity supply. It does not, however, answer the more uncomfortable question raised by the breach.

The immediate consequence was negligible. The capability demonstrated was not.

For Tehran, shutting down a small British power plant for four days may have required comparatively little effort. For Britain’s national security establishment, the episode is a warning that the next target need not be so small — and that the first sign of a serious attack may come only after an adversary has already gained access.

Leave a Comment

You may also like

CLOSE AD

Sign up to our daily news alerts

[ms-form id=1]