Iran-linked hackers shut down UK power generator – should we be worried?

Cyber hackers linked to Iran shut down a UK power plant for four days.

The incident, which occurred in July, involved an unidentified small energy generator, according to The Telegraph.

Hackers unlikely had civilian harm in mind when targeting the power plant, though it is reportedly the first time Iran-linked crooks knocked one offline.

The National Cyber Security Centre, part of the spy agency GCHQ which investigates attacks on infrastructure, declined to comment as it does not routinely acknowledge individual incidents.

Sign up for all of the latest stories

Start your day informed with Metro's newsletter or get alerts the moment it happens.

Energy minister Michael Shanks said on X this afternoon that the hacked site was ‘tiny’ compared to a typical power plant.

‘That being said the generator and the Government took the incident seriously,’ he added.

‘Later in 2026 our wider Energy Resilience Strategy will go further to secure us against a wide range of risks and ensure our resilience for the future,’ Shanks added.

Could hackers target anything else in the UK?

Security experts have long warned that a cyber attack by a foreign country during a time of war isn’t just the stuff of cheap Hollywood films.

Fears of Iranian-linked cyber attacks have been high since the US and Israel launched a deadly attack on Iran in February, igniting a war.

Factories are easy targets for cyber attacks, Steffan Roxrud Thorvaldse, CEO of Qbee, a device management platform, told .

‘Modern factories now operate as “smart” environments where everything is connected, from sensors and cameras to robotics and control systems,’ he said.

SELBY, ENGLAND - JUNE 19: An aerial view of the Drax Power Station in the rural constituency of Selby and Ainsty on June 19, 2023 in Selby, England. Last week, the MP for Selby and Ainsty, Nigel Adams, announced he was standing down with immediate effect. He had already declared he would stand down at the next election. (Photo by Christopher Furlong/Getty Images)

‘That means more ways in for attackers.’

Attackers can gain entry by slipping into security holes in online systems, such as a CCTV camera that uses out-of-date software.

‘From there, attackers can move through networks and potentially interfere with systems that control real-world operations, like factory machinery and production lines,’ Thorvaldse added.

Some experts worry that ‘Iranian hacktivists’, groups which either have ties to or are sympathetic to the regime, could strike.

Richard Ford, CTO of the cybersecurity specialist Integrity360, said: ‘It’s impossible to say what companies could be next and whether any will be in the UK, but the chances of it will depend on the UK’s perceived involvement in the war.

‘Although, as with the war, it is not just the US and Israel being targeted but also their partners and allies.’

A man crosses Tehran's Enghelab Square on July 15, 2026, past a giant anti-US billboard featuring US president Donald Trump in a coffin with text in Persian reading "We Kill Trump". Hostilities renewed between Iran and the US, endangering a memorandum of understanding, reached in June with Qatari and Pakistani mediation, aimed at ending the war. The confrontation resumed on July 7 after attacks on ships in the Gulf, which Iran has attributed to Iran. (Photo by AFP via Getty Images) /

Other experts worry that hacking groups could also be posing as Tehran-affiliated to stir up tensions.

Or they are using the Iran war to pursue their own agendas, such as what a pro-Russian group did by prying open CCTV footage of an Ipswich go-kart track in March.

‘#TimeOfRetribution,’ the group said in a Telegram post at the time, seen by .

Hacktivists can be hired on the dark web, a shady, heavily encrypted corner of the internet away from prying eyes, to knock out websites.

One common – and cheap – hack offered is a distributed denial of service (DDoS), which brought down a massive chunk of the web last November.

Computer vandals jam a website with so many requests that it buckles under the load and becomes unresponsive.

Despite these concerns, experts who specialise in tracking Iranian hacking groups have seen little activity.

Shopper entering a Marks and Spencer food hall on the concourse of Waterloo Station in London UK. April 2026

This was to be expected. The Intelligence and Security Committee, which oversees spy agencies, said last year that while Iran spends millions of dollars on hacking groups, it’s ‘unlikely’ they’d break into British facilities.

The risk of a successful cyber attack against UK infrastructure is between five and 25%, the Cabinet Office said in July.

Still, Ford says it’s vital the government is prepared for cyber attacks, which officials routinely stress that they are.

‘The worst case, which is less trivial to launch and successfully orchestrate, would be a breach of Critical National Infrastructure (CNI) such as electricity, water supply, health services and food supply, and that could have a myriad of effects and be the highest impact felt by Britons,’ Ford said.

‘M&S is a very good example of a cyber attack,’ he added of the Easter breach last year, ‘particularly in terms of severity and impact where shelves were left bare and customers unable to place orders.’

Get in touch with our news team by emailing us at webnews@metro.co.uk.

For more stories like this, .

MORE: OpenAI’s rogue robot tried to hack into other companies – could your data be next?

Original source Iran-linked hackers shut down UK power generator – should we be worried?

Back to home