A reported Iran-linked cyberattack forced a small UK power generator offline for four days, marking a potential escalation in threats to connected industrial systems. The UK government confirmed that a small-scale generator was affected but said the wider electricity system was not endangered; it did not identify the facility or confirm whether operational-control systems were directly compromised. Reporting indicated attackers may have reached an internet-exposed programmable logic controller (PLC) using default credentials before changing its configuration and locking out access.
The incident follows National Cyber Security Centre reporting of more than 200 cyber incidents affecting UK critical infrastructure in the prior year, roughly three-quarters of which were believed to involve state actors. Organizations operating IT and operational technology should remove OT assets from public internet exposure, eliminate default credentials, enforce MFA and least privilege, segment IT and OT networks, tightly control remote access, prioritize high-risk patches, and test offline backups and incident-response procedures—including authority to isolate suppliers or disconnect affected systems.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
The NCSC reportedly warned that UK critical infrastructure experienced more than 200 cyber incidents over the preceding year, with around three-quarters believed linked to state actors.
Following the generator incident, the UK government and National Cyber Security Centre urged critical-infrastructure and industrial organizations to audit internet-facing devices and improve cyber hygiene, including removing exposed OT assets and eliminating default passwords.
Reporting indicated attackers scanned for internet-exposed PLCs, used default credentials to access them, and reset programming while changing passwords and IP addresses to make devices inaccessible. It remained unclear whether operational control systems were directly compromised or the plant was disconnected during IT incident containment.
A reported cyberattack attributed to Iranian hackers forced a small UK power generator offline for four days. Sources differ on whether the outage occurred in July or August; the UK government said the wider energy system was not at risk and did not identify the facility.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.