Iran-linked hackers managed to shut down a British power plant for four days in July 2026. The story was broken by the Telegraph newspaper on August 22, 2026. That it took so long to become public knowledge immediately says two things. Firstly, it was not a major power plant since the effect would have been immediately noticed, and secondly, the authorities wished to keep news of the attack as low key as possible.
Other newspapers (for example the BBC, the Guardian and the Financial Times) have since published their own stories, largely based on the Telegraph account. There has been virtually no information coming from the expected official sources, such as the NCSC. The BBC report comments, “While the Western cyber-security world is braced for attacks either from the state [of Iran] or hackers linked to the state as a result of its conflict with the US this year, there has been little activity so far.”
This last point is clearly wrong. Since the outbreak of the war with US / Israel, Iran affiliated cyber groups have attacked multiple targets in the US (water, critical infrastructure and military-linked assets), Israel (military, government, energy, healthcare, and more), GCC targets in UAE, Bahrain, Kuwait, Qatar, Saudi Arabia, and Europe (Cyprus, Romania and now Britain). This does not equate to ‘little activity so far’, so the expansion into the UK should not be downplayed. And, in general, cybersecurity experts are not downplaying it.










