How did Iran manage to knock a UK power generator offline for four days, and what does it mean for other critical infrastructure? The experts weigh in
Just days before the FBI issued a warning over Iranian attempts to hack critical infrastructure in the US, a UK power generation plant was taken offline for four days after a cyberattack.
The attack has been attributed to Iran, which has stepped up its offensive cyber warfare efforts since the US and Israel began conducting strikes in February 2026.
These cyberattacks have been largely focused on the US and its allies.
A UK government spokesperson responded to the attack, stating, “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.
The U.K. has a highly resilient energy system.
We work closely with the energy sector to protect infrastructure and ensure the highest security standards,” (via CNBC ).
The wider impact for critical infrastructure While the attack may have only targeted a ‘small-scale energy generator’, it shows that state-sponsored groups are actively attempting to disrupt UK energy production in any way they can, regardless of how much power it provides.
As has been made abundantly clear in the US, much of the world’s major critical infrastructure relies on small network-enabled operation technology (OT) components.
If OT devices have passed their end-of-life and no longer receive software updates, or have simply been misconfigured, these devices can show up on the internet to a hacker looking for a way into a protected network. (Image credit: Future) Got an opinion for us? Here’s how you can submit your perspective The UK has taken very careful steps to shield these devices from the internet to prevent them being used to access critical infrastructure, but it only takes a single internet-facing OT to cause issues.
Following the aftermath of the attack, the UK’s National Cyber Security Centre has issued new guidance on protecting OT devices from state-sponsored threats.
In its guidance , the NCSC said “the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.” So what do the experts think the attack means for critical infrastructure, the UK, and the wider world? Expert perspectives on UK powerplant attack Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress: Attackers don’t care whether an energy operator is large enough to meet a reporting threshold.
If it can be disrupted, it can be targeted.
The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.