London – Iranian-linked hackers have successfully brought down a major power plant in the United Kingdom for the first time, according to multiple British media outlets. The Telegraph and Financial Times reported the incident, which occurred in July but is now being formally documented, and is believed to be the most significant cyberattack on PLCs – programmable logic controllers – in the country.
The breach, which has been described by industry experts as a significant escalation, has impacted dozens of states, including New Jersey, Minnesota, Georgia, and South Dakota, effectively locking out operators and causing pressure loss and flooding. CBS News reached out to the U.K.’s National Cyber Security Centre (NCSC) for comment, but it declined to provide a statement or deny any involvement.
U.S. officials and individuals familiar with the matter in the UK have confirmed that computers called “programmable logic controllers” – PLCs – were targeted, according to U.S. officials and people familiar with the situation within the UK. PLCs are ubiquitous in industries ranging from energy and water to manufacturing, and are vital components of automated industrial systems that control everything from hospitals supplying power outages to chemical plants regulating temperature and pressure to prevent explosions and elevator and train speed control.
Industry estimates on the total number of PLCs in use worldwide vary considerably, ranging from roughly 12 million to over 70 million, according to market research firms. The first model was manufactured in the late 1960s and many older units remain in use today. However, security researchers highlight that the methods hackers use to breach PLCs are not sophisticated. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported that Iranian-linked actors are using simple techniques – scanning for exposed devices and exploiting default credentials – rather than deploying sophisticated exploits designed to target vulnerabilities in company networks. CISA has also stated that the responsibility for securing this equipment has largely fallen on individual plant operators, often small utilities with limited cybersecurity expertise, for devices that were never designed with security as a priority in the first place. A 2024 scan by cybersecurity researchers found thousands of PLCs sitting exposed on the open internet.
The first incident on the British power plant involved a four-day outage as employees worked to restore control. British officials and industrial executives have not disclosed which plant was affected, but it is understood the attack targeted a small-scale facility and did not impact the U.K.’s overall power supply. No organization has claimed responsibility, but security experts suggest that these attacks may be proof-of-concept attempts – testing how to navigate the systems of more vulnerable targets before attempting to reach more sensitive, high-value ones in the future.”
The UK has long warned of Iranian-linked cyber activity. In 2022, officials condemned Iran for a cyberattack that crippled Albania’s government services. But the warnings have intensified in early this year, triggered by the U.S.-Israel war against Iran and the killing of Supreme Leader Ayatollah Ali Khamenei. Dr. Richard Horne, head of the U.K.’s National Cyber Security Centre, disclosed that it had ‘managed’ over 200 cyberattacks against UK critical infrastructure in the past year, with roughly 75% of those attacks linked to hostile states including Russia, China, and Iran.
Watch Related Video
Source: CBS News




















