Fiber optic cables are connected to a switch inside a telecommunications room in an office in London, England, Monday, October 13, 2025. Photographer: Jason Alden/Bloomberg via Getty Images
Bloomberg | Bloomberg | Getty Images
A small power station in the UK was shut down for four days in July following a cyberattack by Iranian-linked hackers, the Telegraph reported on Sunday.
The incident came at a time when U.S. authorities, including the Federal Bureau of Investigation, were warning of malicious cyberattackers targeting water utilities in at least seven states, the newspaper said. The Cybersecurity and Infrastructure Security Agency, FBI, Environmental Protection Agency and others condemned Iran.
A British government spokesperson declined to specify the cause of the reported power outage or to identify the facility.
“This story concerns an incident that affected a small energy generator, and there was no risk to the broader energy system,” a spokesperson told CNBC in a statement. “The UK has a resilient energy system and we are working closely with the energy sector to protect our infrastructure and ensure the highest safety standards.”
The government’s Department for Energy Security and Net Zero said it had written to energy sector CEOs and advised companies on next steps. It also said it was updating cybersecurity regulations.
Shortly after the United States and Israel began their war against Iran on February 28, cyber experts warned of online attacks from Iran against American businesses and infrastructure.
On August 18, the U.S. Department of Justice indicted 17 Iranians for conducting “a large-scale cybertheft campaign on behalf of the Islamic Revolutionary Guard Corps and other Iranian organizations.”
Iran is also a target of cyberattacks.
Blockchain analysis firm Elliptic announced in June that Novitex, Iran’s largest cryptocurrency exchange, had been hacked and more than $90 million had been stolen.
Elliptic said the funds were leaked from wallets on the platform to addresses with anti-government messages that explicitly referenced the Revolutionary Guards and suggested a politically motivated cyber attack.
The pro-Israel hacker group Gonjeschke Dalande, also known as Looting Sparrow, claimed responsibility for the attack.
