Iran-linked hackers blamed for taking down U.K. power plant for first time, reports say
London - Iranian-affiliated hackers successfully but temporarily took a power plant offline in the United Kingdom, according to multiple British media outlets.
The Telegraph and Financial Times reported the attack, which they say happened in July but is only now being reported, is believed to be the first time Iranian-linked hackers managed to shut down such a facility in the country.
Of further concern, the breach also happened the same month Iranian-linked hackers are believed to have targeted the water systems of a dozen states including New Jersey, Minnesota, Georgia and South Dakota, locking out operators and causing pressure loss and flooding.
CBS News reached out to the U.K.'s cybersecurity agency, the National Cyber Security Centre, but it neither confirmed nor denied any hacking had occurred.
In both attacks, computers called "programmable logic controllers" were targeted, according to U.S. officials and people familiar with the matter in the U.K. Also known as PLCs, these are the brains of automated industrial systems found around the world that in large part span energy, water and manufacturing. But they are also used ubiquitously in hospitals to help supply power in blackouts, in chemical plants to control temperature and pressure to avoid explosions and in elevators and trains to control speed. PLCs are also employed to control prison security gates, in the timing of traffic light systems and in the activation of fire suppression systems.
Industry estimates on how many PLCs are in use worldwide vary widely, from roughly 12 million to more than 70 million, according to market research firms. The first model was manufactured in the late 1960s — and many older units still in use today were never designed with 21st century cybersecurity challenges in mind.
Yet, security researchers say the methods hackers use to breach PLCs are not sophisticated.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported Iranian-linked actors are using simple techniques that include scanning for exposed devices and exploiting default credentials — default passwords that have not been changed — rather than deploying sophisticated exploits of holes that companies may not know exist. The strategy is more akin to looking for unlocked doors versus high-tech hacking.
CISA has also said the responsibility for securing this equipment has largely fallen on individual plant operators - often small utilities with few to no dedicated cybersecurity staff - for devices that were never built with security as a priority in the first place. One 2024 scan by cybersecurity researchers found thousands of PLCs sitting exposed and searchable on the open internet.
In the attack on the British power plant, that system was offline for four days as employees worked to restore control, reports said. British officials and industrial executives have not disclosed which plant was hit, but it is understood the attack targeted a small-scale facility and did not impact the U.K.'s overall power supply. No organization has claimed responsibility, but security experts say it is possible these attacks may be proof-of-concept attempts — testing how to navigate the systems of more vulnerable targets before attempting to reach more sensitive, high-value ones in the future.
For years, the U.K. has warned of Iranian-linked cyber activity. In 2022, officials condemned Iran for a cyberattack that crippled Albania's government services. But the warnings sharply intensified early this year, triggered by the U.S.-Israel war against Iran and the killing of Supreme Leader Ayatollah Ali Khamenei.
In June, the head of the U.K.'s National Cyber Security Centre, Dr. Richard Horne, disclosed it had "managed" more than 200 cyberattacks against UK critical infrastructure in the past year, with roughly 75% of the attacks linked to hostile states including Russia, China and Iran.