Iranian Hackers Just Turned Off a British Power Plant

By  
Gigabit Systems
August 25, 2026
20 min read
Share this post

Iranian Hackers Just Turned Off a British Power Plant

The hackers didn’t steal the data. They stopped the machine.

For years, we’ve talked about cyberattacks as though the worst thing that can happen is somebody stealing your information.

Your passwords get stolen.

Your customer database gets leaked.

Your files get encrypted.

Your credit card gets compromised.

But there’s another category of cyberattack that should make every business owner considerably more uncomfortable:

The computer gets hacked—and something in the physical world stops working.

That reportedly just happened in Britain.

Iran-linked hackers successfully forced a small British energy facility offline for four days, according to reporting this weekend.

Employees reportedly spent those four days getting the facility operational again.

The plant hasn’t been publicly identified.

The exact vulnerability hasn’t been disclosed.

And British officials say the facility was small enough that the attack never threatened the country’s overall electricity supply.

That’s reassuring.

But don’t miss what actually happened.

Someone sitting behind a computer reportedly reached across the internet and stopped an energy facility from operating.

This Wasn’t a Nationwide Blackout

That’s important.

Some headlines make this sound as though Iranian hackers nearly turned Britain’s lights off.

That’s not what the available reporting says.

A government source characterized the affected generator as extremely small relative to overall grid capacity, and the government says there was “at no point” a risk to the wider British energy system.

So this wasn’t:

London goes dark.

Hospitals lose electricity.

Millions of homes lose power.

The national grid collapses.

But cybersecurity professionals shouldn’t dismiss the incident because it was small.

In some ways, the small scale is what makes it interesting.

You Don’t Test a Capability on the Biggest Target First

We don’t yet know the attackers’ actual objective, so this part is important to distinguish from the reported facts.

But from a cybersecurity perspective, a smaller facility can be an attractive target.

Why?

Potentially weaker security.

Older operational technology.

Fewer cybersecurity personnel.

Legacy remote-access systems.

Less sophisticated monitoring.

Third-party vendors.

Equipment designed decades before anyone imagined connecting it to the internet.

An attacker doesn’t necessarily begin by trying to shut down an entire national grid.

They may begin by proving:

Can we get in?

Can we reach operational systems?

Can we manipulate them?

Will anyone detect us?

Can we force the operator to shut something down?

Those answers can be extraordinarily valuable.

The Difference Between IT and OT

This story is a perfect example of something businesses increasingly need to understand.

IT is Information Technology.

Laptops.

Email.

Microsoft 365.

Servers.

Databases.

Applications.

OT is Operational Technology.

These are computers controlling physical processes.

Pumps.

Valves.

Generators.

Motors.

Production equipment.

HVAC systems.

Industrial machinery.

Water treatment systems.

Electrical infrastructure.

Building automation.

When someone compromises IT, information can disappear.

When someone compromises OT:

Things can move.

Things can stop.

Pressure can change.

Production can halt.

Buildings can become unusable.

And in extreme environments, people can get hurt.

This Is Why Critical Infrastructure Is Such an Attractive Target

Imagine trying to pressure another country using conventional military force.

Aircraft.

Missiles.

Ships.

Personnel.

Logistics.

Enormous expense.

Enormous geopolitical consequences.

Now compare that with cyber operations.

A relatively small team may potentially probe thousands of organizations remotely.

Find exposed infrastructure.

Search for known vulnerabilities.

Steal credentials.

Compromise vendors.

Establish persistence.

Wait.

That’s what makes cyber capabilities so strategically valuable.

The attacker doesn’t necessarily need to destroy infrastructure.

Sometimes merely demonstrating that they can reach it changes the calculation.

The Timing Makes This More Interesting

The British incident reportedly occurred in July, around the same period as attacks against water and wastewater infrastructure across 12 U.S. states that were also linked in reporting to Iranian actors.

That doesn’t automatically prove every incident was coordinated by the same people.

But it reinforces a broader point.

Critical infrastructure is now part of the cyber battlefield.

Water.

Electricity.

Telecommunications.

Transportation.

Healthcare.

Manufacturing.

These aren’t hypothetical targets.

They’re networks.

And networks can be attacked.

Your Business Probably Has OT Too

This is where SMB owners tend to tune out.

They hear:

“Iran hacked a British power plant.”

Interesting story.

Nothing to do with me.

Except many businesses have their own miniature versions of operational technology.

Your building may have:

Internet-connected HVAC.

Door-access systems.

Security cameras.

Elevators.

Lighting controls.

Generators.

Environmental monitoring.

Manufacturing equipment.

Warehouse systems.

Refrigeration.

Building management systems.

Network-connected controllers.

And there’s one question I love asking:

Who is responsible for securing them?

IT?

Facilities?

The HVAC company?

The electrician?

The alarm company?

Your MSP?

The equipment manufacturer?

Nobody?

That last answer appears far too often.

Please Stop Putting Industrial Equipment Directly on the Internet

This should be basic cybersecurity hygiene.

If a piece of equipment doesn’t need to be publicly accessible from the internet:

Don’t expose it.

Operational systems should be segmented.

Remote access should be tightly controlled.

Default passwords should be removed.

MFA should be used wherever technically possible.

Vendor accounts should be reviewed.

Unused services should be disabled.

Firmware should be maintained.

Logs should be collected.

Internet-facing devices should be inventoried.

Backups of critical configurations should exist.

And businesses should know how to operate manually when automation disappears.

That last one matters enormously.

Ask Yourself One Uncomfortable Question

Suppose your building automation system stopped working tomorrow.

Not forever.

Four days.

What happens?

Can you still enter the building?

Can employees work?

Does refrigeration continue?

Does manufacturing stop?

Can you control HVAC?

Can doors be opened manually?

Can alarms function independently?

Can equipment be operated locally?

Do you even know who to call?

Cybersecurity resilience isn’t merely preventing an attacker from getting in.

It’s knowing how the business operates after they do.

Network Segmentation Can Turn a Disaster Into an Annoyance

Imagine a manufacturing company.

Its office computers and production equipment all sit on essentially the same flat network.

Someone compromises an employee laptop.

Now the attacker begins moving laterally.

Production controllers are reachable.

Security cameras are reachable.

Building systems are reachable.

Servers are reachable.

Backups are reachable.

One compromised employee becomes a company-wide problem.

Now imagine proper segmentation.

Employee computers live here.

Servers live here.

Production equipment lives here.

Security cameras live here.

Building automation lives here.

Guest Wi-Fi lives somewhere completely separate.

Traffic between those environments is tightly controlled.

The attacker compromises the same laptop.

But now:

The walls matter.

Segmentation doesn’t magically prevent cyberattacks.

It prevents one cyberattack from automatically becoming everybody’s problem.

Vendor Remote Access Is a Huge Blind Spot

This deserves special attention.

Operational equipment often needs maintenance.

So the installer says:

Don’t worry. We can remote into it if anything breaks.

Wonderful.

Now ask:

How?

What remote-access product?

Whose account?

Is MFA enabled?

Is the account shared?

Does the vendor have permanent access?

Can you see when they connect?

Is access restricted to their equipment?

When was the password last changed?

What happens when one of their employees leaves?

Does your MSP even know this connection exists?

Businesses routinely secure their own employees while leaving a permanent digital side door open for a vendor.

Attackers know that too.

Healthcare Should Pay Particular Attention

Healthcare IT doesn’t exist entirely in laptops and servers.

Modern healthcare environments contain enormous amounts of connected technology.

Building controls.

Medical devices.

Imaging systems.

Environmental controls.

Access systems.

Pharmacy systems.

Network-connected equipment.

A cyberattack doesn’t have to steal patient records to become an emergency.

If technology affects the delivery of care, availability becomes a cybersecurity issue.

Healthcare organizations need downtime procedures that assume certain technology simply won’t work.

Not for ten minutes.

For days.

Schools Have the Same Problem

Schools increasingly contain connected:

Door systems.

Cameras.

HVAC.

PA systems.

Phones.

Digital signage.

Attendance systems.

Network infrastructure.

Classroom technology.

A cyberattack against a school isn’t merely a data-protection issue.

It can become an operations problem very quickly.

School Technology teams need to know which systems are critical, which networks they’re connected to and how the building functions if those systems become unavailable.

SMB Manufacturers Should Be Extremely Careful

Manufacturing is where the IT/OT distinction becomes particularly dangerous.

Production equipment may last:

10 years.

20 years.

30 years.

Sometimes longer.

The machine may still work perfectly.

The operating system controlling it may be ancient.

That’s a cybersecurity nightmare.

You can’t simply tell the owner:

“Replace the $900,000 machine because Windows is old.”

Instead, cybersecurity architecture becomes critical.

Isolate it.

Restrict communication.

Monitor it.

Control remote access.

Prevent unnecessary internet connectivity.

Limit who can reach it.

Assume it cannot defend itself.

Legacy equipment needs modern protection around it.

Have a Manual Mode

One detail from recent attacks on critical infrastructure keeps coming back to the same lesson:

Manual operations matter.

If automation fails, can humans continue?

Businesses have become extraordinarily dependent on technology.

That’s efficient.

Until the technology disappears.

Your incident-response planning should include:

How do we operate without this system?

Print the procedure.

Don’t store the only copy on the server that just got encrypted.

Keep emergency contacts somewhere accessible.

Know how to disconnect critical equipment.

Know how to restore configurations.

Know who has authority to shut something down.

And practice it.

Four Days Is a Long Time

Think about your own business.

Imagine your core operational system disappeared tonight.

Tomorrow: unavailable.

Day two: unavailable.

Day three: unavailable.

Day four: still unavailable.

Payroll.

Orders.

Phones.

Email.

Production.

Customer records.

Scheduling.

Building access.

What starts breaking?

That’s the exercise I want SMB owners to perform.

Not:

“Could Iran hack my company?”

That’s the wrong question.

Ask:

“What technology could shut my business down for four days?”

Then protect that technology accordingly.

Cybersecurity Is No Longer About Protecting Computers

That’s the larger lesson.

Twenty years ago, cybersecurity largely meant protecting information stored on computers.

Today computers control the physical world.

Electricity.

Water.

Factories.

Hospitals.

Buildings.

Transportation.

Communications.

Supply chains.

When those computers are compromised, the consequences don’t necessarily stay inside the computer.

According to the current reporting, this particular attack involved a small British generator and never threatened the national power supply.

Good.

But somebody reportedly still demonstrated that they could turn a functioning energy facility into a nonfunctioning one for four days.

That’s the line businesses should pay attention to.

The next cyberattack may not steal your data.

It may simply turn off the thing your business cannot operate without.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #CriticalInfrastructure #ManagedIT #DataProtection #CyberAttack


Iranian hackers didn’t steal files from this power plant. They turned the plant off—for four days.

Share this post
See some more of our most recent posts...