```html ```
top of page

Iran-Linked Hackers Held a UK Power Plant Down for Four Days in July. Nobody Told Anyone Until Saturday. The Small Plant Is the Message.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 1 day ago
  • 5 min read

The Telegraph broke it on August 22. Iran-linked hackers shut down a British power plant for four days in July 2026. Staff spent those four days restoring it. The plant was small, the wider grid was unaffected, and UK officials would not name the facility. The NCSC said close to nothing. The reporting describes it as the most successful cyberattack of its kind against UK energy infrastructure, and the first time actors affiliated with the Iranian regime are believed to have closed such a facility in the UK.


There is a version of this story that treats "small plant, no grid impact" as the reassuring part. That reading is exactly backwards, and getting it right requires knowing something about how this particular set of actors works — which, as it happens, we have been documenting all year.



The small plant is not a failure to hit a big one


If your goal is to cause a blackout, you attack a facility whose loss causes a blackout. If your goal is to demonstrate that you can, you attack the one where the demonstration is unambiguous and the escalation is survivable.


Four days is the tell. Not four minutes, not a flicker, not a nuisance trip that engineers could argue was a fault. Four days of a facility staying down while staff worked to bring it back is a duration chosen to be undeniable — long enough that the operator knows exactly what happened, short enough and small enough that no government is forced to treat it as an attack on the population. The assessed intent in the reporting is precisely this: showing that IRGC-affiliated actors can reach UK infrastructure and shut it down at will.


That is not a failed attempt at something bigger. It is a message delivered at a carefully chosen volume, and the recipient list is every other operator in the country.



We have been describing this exact capability since April


This is our standing beat, so here is the arc rather than a fresh take.


On April 13 we published on joint advisory AA26-097A — FBI, CISA, NSA, EPA, DOE and US Cyber Command — under the title "4,000 US Industrial Devices Exposed to Iran. They're Not Using Zero-Days. They're Reading the Manual." The argument then, and it holds now: IRGC-affiliated actors were not burning exotic capability. They were connecting to internet-exposed programmable logic controllers and operating them as designed, because the devices were reachable and the default credentials had never been changed.


On May 9 we wrote that Iran's two cyber wings were running ICS campaigns simultaneously, and that CISA had confirmed it.


On July 25 we covered CISA's update to AA26-097A, and specifically the paragraph nobody picked up: the detection guidance everyone quoted was about Rockwell reusable code modules, but the more important content described attackers leaving ladder logic running while deleting the safety limits. Not destroying the process — removing the constraints that keep the process safe, and letting it continue.


On July 31 we ran our own check: we had told water operators to look at ports 44818, 2222, 102 and 502, and we had never run that check against our own attacker list. We did. It was there.


The July attack in the UK is that capability, used. Everything published in advance said the access route was exposure and default configuration rather than novel exploitation, and that the actors were in a demonstration posture rather than a destruction posture. A small plant, held down for four days, and no attempt to hide that it happened, is the demonstration posture arriving in Britain.





What we do not have, said plainly


No indicators. UK officials did not name the plant, no technical detail on initial access has been published, and no IOCs, malware hashes or attacker infrastructure have been released by anyone. We have checked our own corpus and we have nothing attributable to this incident, because there is nothing published to attribute.


We are not going to reach into our Iran collection, pull IRGC-adjacent infrastructure we hold for other campaigns, and imply it relates to a British power station. That would be exactly the kind of laundering we have written rules against, and it would be wrong.


What we have is the shape, documented across four months and four posts before this incident surfaced, and the shape is what is actionable tonight.



What an operator should actually do this week


None of this requires a budget, which matters because the facilities in this category rarely have one.


Find out what of yours is reachable from the internet, and be honest about the answer. The April advisory's core finding was 4,000 exposed industrial devices in the US alone. The exposure is the vulnerability. Check ports 44818 (Allen-Bradley / Rockwell EtherNet/IP), 502 (Modbus), 102 (Siemens S7) and 2222, plus 22 on cellular modems and any remote-access appliance a vendor installed and nobody has logged into since commissioning.


Change the default credentials. It reads as insultingly basic and it is the documented access route in the advisory. Reading the manual only works if the manual's defaults are still in place.


Then check your safety instrumentation against a known-good baseline, because of the July guidance. An attacker who leaves the process running and deletes the limits produces no alarm, no outage and no obvious symptom until the day the limit was the only thing standing between you and an event. Compare the running configuration against what it is supposed to be. Most operators have never done this even once.


And assume the reporting delay is normal. This attack happened in July and became public on 22 August — roughly four weeks — and the article notes authorities appeared to keep it as low key as possible. That is a reasonable institutional instinct and it has a real cost: every other operator in the country lost four weeks of warning. If you are waiting for official notification to tell you that your sector is under attack, you are structurally behind.


Capped where we always cap it at 95 percent: attribution here is press reporting and expert assessment, not an official NCSC or government confirmation. "Iran-linked" is doing real work in that sentence and we are leaving it there rather than upgrading it. We have no first-party visibility into this incident.



Sources


The Telegraph broke the story on 22 August 2026; subsequently covered by SecurityWeek, Security Affairs, RTÉ, CNBC and the Times of Israel. Attack occurred July 2026; four-day outage; facility unnamed by UK officials; no wider grid impact. Reporting notes concurrent Iranian activity against US water infrastructure and suspected operations in Germany, Poland, Finland, Belgium and Albania.


Our own prior coverage of the same beat: AA26-097A and the 4,000 exposed devices (13 April 2026), Iran's two cyber wings running simultaneous ICS campaigns (9 May 2026), the deleted safety limits in the AA26-097A update (25 July 2026), and our own port 44818 check against the attacker list (31 July 2026).




If you operate a small generation, water or process facility and you go and check those ports this week, I would like to know what you found — especially if the answer is that something is exposed that you did not know was exposed. That is the most common outcome and the least often admitted. Rate this post below.




How do AI models see YOUR brand?

AIPM has audited 250+ domains. 15 seconds. Free while still in beta.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=iran-linked-hackers-held-a-uk-power-plant-down-for-four-days-in-july-nobody-told-anyone-until-satur



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page