Iran-Linked Hackers Knock UK Power Plant Offline, Hit US Water Systems in Coordinated Campaign
Suspected IRGC-affiliated group CyberAv3ngers shut down a British energy site for four days in July while simultaneously disrupting wastewater utilities across 12 US states, in what researchers assess as deliberate capability demonstrations.
A suspected Iran-linked cyberattack took a small UK power plant offline for four days in July 2026, becoming public only after The Telegraph broke the story on August 22. The timing matters: the UK incident overlapped almost exactly with a wave of intrusions against water infrastructure across 12 American states.
According to a report reviewed by The Register, a British government spokesperson confirmed the hack and described the affected facility as a "small-scale energy generator." UK Energy Minister Michael Shanks said his department briefed energy CEOs after the incident and shared guidance on protective steps. The government did not name the plant, citing security concerns, and the UK has not formally attributed the attack to Iran or to any specific group.
On the attribution question, confidence is moderate at best. Private-sector threat analysts told The Register that Iran is "almost certainly" behind the US water breaches, characterizing them as a direct response to the ongoing Middle East conflict. The FBI attributed the US water incidents to "malicious cyber actors," and US government sources separately confirmed to SC Media that the threat most likely originated in Tehran. That's two layers of attribution, neither of which is a formal public designation. Read them accordingly.
The group most analysts point to is CyberAv3ngers, which The National News reported is affiliated with the IRGC's Cyber-Electronic Command. Cybersecurity firm Tenable found the group repeatedly targets small utilities and rural operators that expose systems directly to the public internet. The specific hardware implicated in past CyberAv3ngers campaigns, Unitronics Vision-series programmable logic controllers, is used across water, wastewater, energy, and manufacturing sectors. No official has confirmed those PLCs were the vector in these specific incidents.
In the US, the scale of the water-sector hit was real. Security Affairs reported that dozens of wastewater treatment plants across 12 states were affected, with flooding and loss of water pressure forcing boil-water advisories in affected areas. The first reports surfaced from Minnesota on July 26, followed by Michigan, Georgia, South Dakota, and New Jersey, among others.
The UK power outage lasted four days before staff restored the plant. Security Affairs assessed that the UK attack was probably not designed to harm civilians, but rather to demonstrate that IRGC-linked actors could access UK infrastructure and shut it down on demand, a proof-of-concept framing, not a maximalist strike. That's a plausible read, but it's an analytical judgment, not a confirmed statement of intent.
What's harder to brush off is the four-day recovery window. As SecurityWeek noted in its analysis, that timeline at a facility classified as non-critical raises questions about the resilience baseline across the rest of distributed UK energy infrastructure, the sites that would matter if an adversary decided to stop demonstrating and start disrupting.
The UK's Cyber Security and Resilience Bill is currently moving through Parliament and is expected to pass into law before the end of 2026, according to Help Net Security, though meaningful effect on operator posture is still years away. The NCSC wrote directly to energy companies with guidance following the attack. Whether those companies act on it is a separate question, and not one any government spokesperson is positioned to answer honestly.
Sources cited:
- The Register (https://www.theregister.com/security/2026/08/24/iran-linked-cyberattack-shut-down-a-uk-power-plant/5291930)
- Security Affairs (https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html)
- SC Media (https://www.scworld.com/brief/iran-linked-hackers-target-uk-power-plant-and-us-water-infrastructure)
- The National News (https://www.thenationalnews.com/news/uk/2026/08/24/uk-energy-alert-issued-after-iranian-cyber-attack-on-power-plant/)
- SecurityWeek (https://www.securityweek.com/iran-linked-hackers-shut-down-uk-power-plant-for-four-days/)
- Help Net Security (https://www.helpnetsecurity.com/2026/08/24/uk-power-plant-cyberattack/)
This release was originally distributed via ETL Newswire. Visit The Register for the full story, related releases, and contact information.
Visit The Register →