A small UK power plant was reportedly forced offline for four days after an intrusion attributed to Iran-linked hackers, marking what has been described as the first confirmed cyber-induced shutdown of a British power facility. The outage did not affect the broader electricity grid, but the incident was reported to the UK's National Cyber Security Centre and prompted warnings to energy operators about heightened risks to critical infrastructure.
The activity coincided with a broader wave of suspected Iranian operations targeting water and wastewater systems in the United States, where officials linked attacks across 12 states to flooding, pressure loss, and boil-water advisories. In New Jersey, Hamilton Township Municipal Utilities Authority disclosed a cyber threat and said the extent of unauthorized access remained unclear, adding to concerns that water utilities are among the sectors facing sustained hostile probing and disruption.

See the actors and campaigns active against you right now.
10 events from the most recent confirmed update back to the earliest known activity.
The first reports of cyber incidents affecting U.S. water infrastructure came from Minnesota on July 26. The broader campaign was later described as affecting wastewater facilities across 12 states and causing flooding, pressure loss, and boil-water advisories.
During the July campaign against U.S. water and wastewater systems, some intrusions reportedly enabled attackers to modify PLC configurations and disable shutdown processes and alarms. The activity affected PLCs from Rockwell, Schneider Electric, and Siemens and caused outages and operational disruption during incident response, though reported effects on water supplies were limited.
CISA reported that Iranian-linked malicious activity in July 2026 targeted more than 100 internet-exposed U.S. water and wastewater-sector systems, commonly targeting PLCs directly connected to cellular modems. CISA issued guidance urging operators to reduce unnecessary internet exposure and secure required remote access with measures including secure gateways, MFA, updated software, non-default credentials, and monitoring.
Five U.S. federal agencies warned that attackers were using AI-generated exploitation scripts against internet-exposed Siemens S7 Series PLCs. The warning identified water, manufacturing, energy, and other critical-infrastructure facilities as targets.
The White House is preparing an Office of the National Cyber Director-led program to help water and wastewater providers strengthen cybersecurity, including private-sector assistance for states with limited resources. Texas may serve as an initial pilot before the effort expands to other requesting states.
Following the power plant incident, the UK government warned power companies and businesses and provided response guidance. The incident was also reported to the National Cyber Security Centre.
Iran-linked hackers reportedly shut down a small British power plant for four days in what was described as the first confirmed successful cyber-induced closure of a UK power facility by actors affiliated with Iran. The outage did not affect the wider UK electricity supply, and staff restored operations after four days.
The FBI attributed the U.S. water-sector incidents to malicious cyber actors. Government sources later assessed that the threat most likely originated in Tehran.
The reported wave of U.S. water and wastewater cyberattacks was confirmed to have affected facilities in Alabama, in addition to Minnesota, Michigan, New Jersey, South Dakota, and Georgia. The article said at least 12 states appeared to have been impacted overall.
After the initial Minnesota reports, similar breaches were reported in Michigan, Georgia, South Dakota, and New Jersey. The incidents were part of a wider wave affecting wastewater infrastructure across multiple states.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
28 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcesecurityaffairs.com
Open sourcetheregister.com
Open sourcemalware.news
Open sourcetelegraph.co.uk
Open sourcedysruptionhub.com
Open sourcencsc.gov.uk
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.