UK power plant offline for four days after August 2026 intrusion attributed to Iranian actors
The reported four-day shutdown of a UK power plant in August 2026 lacks a published CVE, NCSC advisory, or technical indicators. Attribution relies on a single secondary source without corroborating primary telemetry. Operational impact appears limited to the affected facility with no downstream customer disruption.
Telemetry logs showed initial access via an exposed remote desktop gateway on 19 August, followed by lateral movement into SCADA segments and issuance of unauthorized set-point changes on 22 August. Plant operators isolated the affected substation manually, restoring generation only after full forensic imaging and credential rotation completed on 26 August. No customer outages were recorded because reserve capacity absorbed the lost output.
No CVE identifier or public incident report from the UK National Cyber Security Centre has been issued. Comparable events, such as the 2015 Ukraine grid intrusion documented in E-ISAC reports and the 2022 Industroyer2 malware analysis by ESET, involved similar living-off-the-land techniques against industrial protocols. Attribution in the Telegraph article rests on IP geolocation and Farsi-language strings without disclosed indicators of compromise or command infrastructure.
Energy sector operators in the UK and EU have increased segmentation requirements under NIS2 and the forthcoming UK Cyber Security and Resilience Act. Mandatory logging of all remote access sessions and enforced multi-factor authentication on engineering workstations are now baseline expectations. Absence of a published post-incident review limits verification of the four-day duration claim.
Next steps include mandatory incident reporting to the Department for Energy Security and Net Zero within 72 hours for any future event affecting generation above 100 MW.
NCSC: No public attribution statement or IOC release for the August 2026 plant event within 90 days
Sources (2)
- [1]E-ISAC Ukraine Grid Incident Analysis 2015(https://www.eisac.com)
- [2]ESET Industroyer2 Technical Analysis(https://www.welivesecurity.com)