The UK is responding to a cyberattack that knocked a small gas-fired power generator offline for four days in July 2026. According to reports by the Financial Times, hackers linked to Iran are believed to be behind the attack. The British government has confirmed the incident but not the identity of the perpetrators. The facility’s location and operator remain unknown. Electricity customers were not affected, and the national grid reportedly remained stable throughout.
Cyberattack exposes security gaps in small energy facilities
After the incident came to light, Energy Minister Michael Shanks briefed the heads of British energy companies on additional protective measures. He emphasized that the affected generator was small compared to standard power plants; nevertheless, the digital intrusion resulted in an actual operational outage lasting four days.

Image: Shutterstock
According to the Financial Times, the facility in question was a gas-fired peak-load power plant—a so-called “peaker.” Such plants provide additional power on short notice when electricity demand surges. Furthermore, many of these facilities employ automated control systems, making them potentially attractive targets for attacks on operational technology.
London Plans to Expand Cyber Rules for Energy Companies
This incident affects a British energy system where, according to government assessments, cybersecurity regulations still contain gaps. Some smaller market participants do not fall under existing NIS requirements. Consequently, London plans to introduce fundamental cybersecurity mandates for all companies licensed by Ofgem.
In the twelve months leading up to May 2026, the NCSC recorded more than 200 incidents involving critical infrastructure. The agency linked approximately three-quarters of these to state-sponsored actors. As a result, a cyberattack on energy facilities now carries security implications that extend far beyond the individual operator.
Attacks on Industrial Control Systems on the Rise
Industrial control systems are also increasingly being targeted internationally. In late July, the FBI warned of attacks on publicly accessible programmable logic controllers (PLCs) at American water utilities. Perpetrators altered passwords and network settings, causing some operators to lose control over and visibility of their facilities.
No such attack method has been confirmed for the British facility to date. However, the cyberattack demonstrates that even small-scale producers can suffer physical outages due to digital interference. Consequently, the UK is expanding its regulations. In the future, regulated companies will be required to report significant incidents within 24 hours and provide a more detailed report after 72 hours. Furthermore, the government plans to extend security requirements to additional parts of the digitized energy system.
Author: Blackout News
Source: Financial Times (25.08.26) – Reuters (24.08.26) – Financial Times (24.08.26)
