July 30, 2026 eBuilder signs a SOC/MDR agreement with a Swedish company in the Energy Sector
July 9, 2026 eBuilder signs a Vulnerability Scanning and Identity Protection agreement with a Transportation company in Finland
June 19, 2026 eBuilder signs a MDR and Vulnerability Scanning with a Media Streaming company in Estonia
May 26, 2026 Swedish eTrade platform signs an agreement for vulnerability scanning
May 21, 2026 Swedish software producer signs agreement for continuous pentesting
May 20, 2026 Swedish CRM producer signs an agreement for continuous penetration testing
May 16, 2026 eBuilder signs an agreement for SOC/MDR with a TechHub
May 11, 2026 eBuilder signs an agreement for SOC/MDR and automated pentests with a company in the publishing business
Company News
Critical Infrastructure

Iran-Linked Attack Took a Small UK Power Plant Offline for Four Days

Date August 24, 2026 / 7 Min Read

A cyberattack took a small British power plant offline for four days in July. The Department for Energy Security and Net Zero has confirmed the outage describing the affected site as a small-scale energy generator and said the wider energy system was never at risk. British officials have linked the attack to Iran. None of them have done so on the record.

The Telegraph published the story on 22 August, reporting that staff spent four days bringing the plant back and that officials would not identify it on security grounds. Energy company executives were briefed and guidance went out to businesses afterwards. The National Cyber Security Centre declined to comment on the incident.

Then a government source explained why the plant had not been obliged to tell anyone. Speaking to The Telegraph, the source said the site sat nowhere near the reporting threshold for important generators calling it “a very small-scale site, less than a rounding error compared to grid capacity.”

The Threshold Defence Is the Story

That claim is legally accurate. The Network and Information Systems Regulations 2018 set capacity thresholds determining which generators must report cyber incidents and a plant this small falls outside them. It also falls outside the reform currently in Parliament. The Cyber Security and Resilience (Network and Information Systems) Bill cleared the Commons in June, had its Lords second reading on 14 July and is expected to receive Royal Assent before the end of the year. It brings managed service providers, data centres and large load controllers into scope, the last of those at a threshold of 300 MW. It does not move the generation threshold.

The gap was already recognised. On 27 March 2026, DESNZ and Ofgem opened a joint consultation on reshaping cyber regulation in downstream gas and electricity, proposing baseline resilience requirements for all Ofgem licensees and an amendment to the NIS designation criteria. The two bodies stated that limiting cyber obligations to a subset of the largest operators no longer made sense. The consultation closed on 22 May. The plant went offline in July.

If the objective was to prove that a British generating asset could be reached and switched off without triggering a single statutory obligation, the target selection was sound.

The Same Week, 30 Minnesota Water Systems Went Manual

The British outage coincided with a campaign against American water utilities. Between 26 and 27 July, more than 30 Minnesota community water systems had their operational technology attacked simultaneously. Minnesota IT Services put the number at roughly 36. Plymouth, South St Paul, Maple Plain and Braham confirmed publicly. The rest were withheld while the investigation runs.

The FBI and the Environmental Protection Agency issued a joint public service announcement on 30 July. Utilities in at least 7 states had reported incidents since 27 July and some of that activity had degraded water operations. Later reporting by CBS News and ABC News put the total at 12 states including Michigan, Georgia, New Jersey and South Dakota.

The method described in the FBI alert is the part worth reading twice. The actors reached internet-facing Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers, changed the IP addresses and passwords and left operators with no monitoring or control. Reported effects included loss of pressure and flooding. One organisation found altered PLC project files after an engineer noticed that the ladder logic did not match across sites.

In Georgia, the Clayton County Water Authority which serves around 300,000 people south of Atlanta, lost pressure and issued a boil water advisory. Service came back within hours.

No zero-day was involved anywhere in this. Kurt Gaudette, head of intelligence at Dragos, characterised the campaign as going after low-hanging fruit, small utilities running default passwords with controllers exposed to the internet. A vendor talking an attack down is worth listening to because the commercial incentive normally runs the other way.

Nobody Official Has Attributed Any of It

The Iran link deserves more care than it is getting. In the British case it rests on unnamed officials quoted by one newspaper. The NCSC has said nothing. DESNZ confirmed the outage and the size of the site and stopped there. In the American case the FBI did not attribute the water attacks to anyone and President Trump publicly disputed the Iran theory in late July. The New York Times reported that investigators considered Iranian involvement likely while noting the assessment was preliminary and that a third party posing as Tehran-aligned could not be ruled out.

What is documented is narrower than the attribution and more useful. CISA, the FBI, the NSA, the EPA, the Department of Energy and US Cyber Command published joint advisory AA26-097A on 7 April 2026 covering Iranian-affiliated actors exploiting internet-connected PLCs across US critical infrastructure. They updated it on 22 July to widen the manufacturer scope from Rockwell to Schneider Electric and Siemens. The advisory ties the activity to the IRGC Cyber Electronic Command and to CyberAv3ngers, the group behind the 2023 compromises of Unitronics controllers at American water facilities.

Sweden Moved Its Threshold the Other Way in January

Cybersäkerhetslagen (2025:1506) came into force on 15 January 2026, implementing NIS2 in Swedish law. Energy is a highly critical sector and the definition is broad, electricity, district heating, district cooling, oil, gas and hydrogen. The size thresholds sit lower than under the old NIS law which pulls a large number of smaller Swedish energy companies into scope for the first time. Energimyndigheten supervises the sector, operators register with Myndigheten för civilt försvar and penalties run to €10 million or 2 percent of global turnover.

Emma Johansson, who leads security work at the industry body Energiföretagen Sverige, made the case for including them without hedging when the law took effect. Her argument, in summary, company size tells you nothing about the consequences of an incident and Sweden has a great many small energy companies. That is the argument the British government spent last weekend making in reverse.

Svenska kraftnät has its own recent lesson in the distance between “no operational impact” and “no problem”. The transmission operator was breached in October 2025 through a separate external file transfer service with the Everest group claiming 280 GB of data. Electricity supply was unaffected. Information security chief Cem Göcgören confirmed that some sensitive data about the electricity system, along with contact details was among what had been exposed. In February, after media reports of a threat to Nordic energy infrastructure, the agency and Energimyndigheten said they knew of no specific threat and told the sector to raise its vigilance anyway.

Start With What Is Facing the Internet

  1. Take PLCs and other operational technology off the public internet. Where remote access is genuinely needed, put it behind a VPN or gateway with MFA rather than exposing the controller itself. This is the first recommendation in both the FBI announcement and CISA’s guidance and it would have stopped most of what happened in Minnesota.
  2. Replace default credentials, then inventory controllers by model. Check Rockwell MicroLogix 1100 and 1400 units against the FBI advisory first, then apply the same review to Schneider Electric and Siemens equipment given the July expansion of AA26-097A.
  3. Compare running ladder logic against known-good project files. The altered project files in the US campaign surfaced only because an engineer spotted logic that did not match between sites.

Then test whether your operators can run the plant by hand. The Minnesota utilities that came through this best were the ones that switched to manual operation fastest.

For tailored threat briefings and incident readiness assessments, contact eBuilder Security.

References

  1. UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
  2. Small UK Power Generator Shut Down After Cyberattack Linked to Iran
  3. Reshaping Cyber Regulation in Downstream Gas and Electricity
  4. Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers
  5. Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
  6. At Least 12 States Report Cyberattacks on Water Systems Possibly Linked to Iran-Backed Hackers

This post is also available in: Svenska