In an unprecedented cyberattack, hackers linked to the Iranian regime managed to disable a British power plant for four days, as revealed by The Telegraph.
It is considered the first time that hackers connected to Tehran have succeeded in deactivating such an infrastructure asset in the United Kingdom, marking the most successful attack of its kind.
According to information from the newspaper, the incident occurred during the same period as a series of attacks on US water infrastructure last month, which affected 12 states and triggered intense concern in the White House.
British officials refused to disclose specifically which power plant was hit, citing security reasons.
However, it became known that the facility was knocked offline for four days while staff battled to restore operations.
The affected plant was relatively small in scale, with the result that the disruption had no impact on the wider electrical grid or energy generation in the United Kingdom.
In response, the British government briefed chief executive officers of energy companies and dispatched letters to businesses containing instructions, guidance, and next steps.
The incident was reported to the National Cyber Security Centre (NCSC), the public-facing arm of intelligence agency GCHQ, which advises companies on protecting national infrastructure from foreign threats.
British and American intelligence agencies have repeatedly warned about the risk posed by hackers from Russia, China, Iran, and North Korea, who daily bombard critical national infrastructure and government departments with attacks.
In the past, severe incidents have disabled systems belonging to the National Health Service (NHS), schools, and industrial manufacturing plants, including production lines of Jaguar Land Rover.
Furthermore, foreign hacker groups have stolen customer data from retail businesses, as well as voter registers from the Electoral Commission.
Nevertheless, no hacker had managed until now to immobilize a British power plant, despite warnings that attacks on national infrastructure are a daily occurrence.
It is considered doubtful whether the attack aimed to inflict real harm on citizens, and it did not appear to be widely noticed by the public.
However, it is likely that the incident was designed to demonstrate that hackers linked to Iran’s IRGC possess the capability to gain access to UK systems and shut down sensitive infrastructure facilities.
Severe consequences in the US
Across Britain, there are dozens of small-scale power plants connected to the grid.
Many of these operate on natural gas and are utilized for only a few hours per week, for example when wind speed is low and supplementary power is required.
A four-day shutdown at such a facility does not impact the wider grid.
Certain factories and other facilities, such as hospitals, also maintain their own separate power generation units.
In the US, attacks affected dozens of wastewater treatment facilities, causing flooding and loss of tap water pressure, forcing certain authorities to advise consumers to boil water before drinking.
The initial reports of the incident appeared in Minnesota on July 26, followed by a series of similar security breaches across Michigan, Georgia, South Dakota, and New Jersey.
The FBI attributed the incidents to «malicious cyber actors», but US government sources later confirmed to media outlets that the threat likely originated from Tehran.
Iran has intensified its cyberattacks against Western nations in the wake of the conflict in the Middle East, particularly after the US and Israel launched airstrikes in February.
Alleged Iranian attacks have been reported in Germany, Poland, Finland, Belgium, and Albania, although Israel and other nations across the Middle East remain the most frequent targets.
In March, the NCSC advised British organizations to review their security strategies in light of the conflict, while Richard Horne, chief executive of the agency, stated in June that the organization handled more than 200 attacks on critical national infrastructure over the previous year.
The NCSC does not systematically confirm individual incidents and declined to comment on the attack against the British power plant.
Experts have long warned that the United Kingdom is unprepared for the scale of the threat posed by malicious cyberattacks from foreign adversaries.
The Intelligence and Security Committee, which oversees the spy agencies, reported last year that the likelihood of an Iranian cyberattack on British infrastructure was «unlikely».
However, the committee also noted that cyber warfare constitutes a «significant area of asymmetric capability» for Iran, which expends tens of millions of dollars on hacker groups, each comprising hundreds of individuals.
An official risk assessment by the Cabinet Office, published last month, found that the risk of a severe and successful cyberattack against domestic infrastructure ranges between 5% and 25%, while warning that «artificial intelligence can automate the process of launching cyberattacks, making them faster, more effective, and lowering the barrier to entry».
A government source stated: «We have thresholds under which major generators are legally required to notify us of cyber activity, and this specific facility sits far below them. It is a very small-scale facility, less than a rounding error compared to the total capacity of the grid».
A government spokesperson attempted to downplay the event and stated: «The United Kingdom possesses an exceptionally resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards. The report refers to an incident that affected a small-scale energy generator, and at no point was there any risk to the wider energy system».
www.bankingnews.gr
Readers’ Comments