Iran-linked hackers have successfully shut down a British power plant for four days, marking the first confirmed cyberattack of its kind against UK energy infrastructure. This incident occurred concurrently with a series of attacks targeting water infrastructure across twelve US states, according to Security Affairs.
The UK power plant, which was not named due to security concerns, was offline for four days before being restored by staff. Although the plant was small and did not impact the wider UK power supply, the incident prompted warnings to power companies and businesses. The attack was reported to the National Cyber Security Centre.
"This attack represents a real escalation and validates many of the prior warnings about the potential risk of state-backed hackers to critical national infrastructure (CNI)," said Euan Carswell, SOC Team Lead at Barrier Networks.
In the US, dozens of wastewater treatment plants in twelve states were affected, leading to flooding and loss of water pressure. The FBI attributed these incidents to malicious cyber actors, with US government sources confirming the threat likely originated in Iran.
The UK attack's intent is believed to be a demonstration of capability rather than direct harm. Iran has increased cyberattacks on Western countries since February, with operations reported in several European nations. Experts have warned of the UK's unpreparedness for such threats, and AI is noted as a factor lowering the barrier for cyberattacks.
"Larger plants and energy providers need to be prepared. Ongoing geopolitical tensions have led to an incredibly high-risk threat landscape, with Iranian hackers given a broad remit and motivation to pursue wins against their adversaries," Carswell said.
"The UK government needs to do everything they can to advise and monitor the ongoing threat to UK CNI, especially to the energy sector, and companies operating in the sector need to ensure they follow advice and ensure strict security practices, if not otherwise compelled," Carswell added.
Source: Security Affairs
Written by
Kelley Damore
Chief Content Officer
CyberRisk Alliance
Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.