Small UK power generator shut after Iran-linked cyberattack: report

Fiber optic cables feed into switches inside a communications room in an office in London, U.K., on Monday, Oct. 13, 2025. Photographer: Jason Alden/Bloomberg via Getty ImagesBloomberg | Bloomberg | Getty Images A small power plant in the United Kingdom was shut down for four days in July following a cyber attack carried out by hackers linked to Iran, The Telegraph newspaper reported on Sunday. The newspaper said the incident occurred around the time U.S. authorities, including the Federal Bureau of Investigation, warned about malicious cyber actors targeting water facilities in at least seven states. The Cybersecurity and Infrastructure Security Agency, the FBI, the Environmental Protection Agency and other agencies blamed Iran. A UK government spokesperson declined to assign blame for the reported power outage or identify the facility. “This story concerns an incident that affected a small-scale power generator, and at no time was there a risk to the broader power system,” the spokesperson told CNBC in a statement. “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest safety standards.” The government’s Department of Energy Security and Net Zero said it has briefed energy chief executives and written to companies to advise them on next steps. It also said it is updating its cybersecurity regulations. Shortly after the United States and Israel launched their war against Iran on February 28, cyber experts warned of online attacks by Iran on American businesses and infrastructure. On August 18, the US Department of Justice charged 17 Iranians with carrying out a “massive cyber theft campaign on behalf of the Islamic Revolutionary Guard Corps and other Iranian entities.” Iran has also been the target of cyber attacks. In June, blockchain analytics firm Elliptic said Iran’s largest cryptocurrency exchange, Nobitex, was hacked for more than $90 million. Funds were drained from the platforms’ wallets to addresses that carried anti-government messages that explicitly referenced the IRGC, pointing to a politically motivated cyberattack, Elliptic said. The pro-Israel hacking group Gonjeshke Darande, or “Predatory Sparrow”, claimed responsibility for the attack. Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.