Key Takeaways:
- In late July, a cyberattack forced a small power generation facility in the UK offline for four days.
- The UK‘s wider grid remained unaffected but the incident exposed a gap at smaller facilities. Small operators often face the same threat actors as major utilities with fewer security resources, lighter regulatory oversight and limited incident-response support.
- Attackers don’t need zero-days to disrupt OT. Internet-exposed controllers, default or weak credentials, legitimate engineering tools and insufficiently restricted remote access can provide a repeatable path to operational impact.
- Basic safeguards can materially reduce risk. Operators should identify internet-exposed assets, change default credentials, restrict remote access, use controller run modes, maintain offline backups and monitor for early-stage reconnaissance.
In late July, a cyberattack forced a small power generation facility in the United Kingdom offline for four days. First reported by The Telegraph and attributed in that reporting to hackers linked to Iran, it is believed to be the first time an Iran-affiliated group has successfully shut down a British electricity-generating facility. The UK government has not named the facility and has not attributed the attack to anyone, but the Department for Energy Security confirmed the incident "impacted a small-scale energy generator," and a government source described the site as "less than a rounding error compared to grid capacity."
The shutdown occurred in July, around the same time the FBI and EPA were warning about attacks on water utilities across 12 U.S. states, and shortly after London granted the U.S. permission to conduct defensive operations against Iran from British bases.
While that description may be accurate on grid impact, it also captures the challenging position small operators are in. Facilities of this size run with small teams and tight budgets, and security competes every day with the work of actually generating power or treating water. These operators face the same threat actors that national utilities do but without the regulatory attention, staffing, or incident support that comes with being large enough to matter to the grid. This incident once again exposes that gap, and there are early signs that smaller operators, not just flagship utilities, are drawing attention.
The Importance of Grid Resiliency
One of the most important takeaways of this incident is a success story: at no point was the wider UK energy system at risk. Great Britain's transmission system is engineered to the NETS Security and Quality of Supply Standard, which requires the system to ride through the sudden loss of its largest single infeed, a figure that was recently raised from 1,320 MW to 1,800 MW to prepare for the Hinkley Point C nuclear reactors coming online. Frequency response reserves, balancing services and decades of engineering discipline mean a small generator dropping offline is absorbed the same way the system absorbs routine equipment trips every week. That resilience is the product of sustained investment by grid operators and regulators, and it worked as designed during the incident.
Some news coverage has not made this clear, but attacks on small operators in the UK will not disrupt grid operations. That doesn’t let the individual facility off the hook: in this case, the plant still lost four days of generation, and its staff spent those four days on cyber response and restoration instead of power operations.
Was the UK Plant Shutdown a Proof of Concept?
If the goal had been grid disruption, a single small operator is not the right target. Analysts quoted in some of the media coverage instead read it as a demonstration that groups aligned with Iran's Islamic Revolutionary Guard Corps (IRGC) could reach a UK generating asset and take it offline, described by one as a "successful proof of concept."
The timing of this attack supports that interpretation. The shutdown occurred in July, around the same time the FBI and EPA were warning about attacks on water utilities across 12 U.S. states, and shortly after London granted the U.S. permission to conduct defensive operations against Iran from British bases. Whether these events were coordinated as part of a larger campaign or simply opportunistic, they fit a pattern Nozomi Networks Labs has tracked for some time: Iran-linked cyber activity rises and falls with kinetic escalation. Nozomi researchers documented a 133% increase in attacks from known Iranian threat actors during the May and June 2025 escalation, and have observed a systematic increase again during the current conflict, with early-stage intrusion behavior dominating: default credential abuse, valid account usage, brute force, scanning. The tempo is not lost on UK authorities. NCSC chief executive Richard Horne has said the agency now handles at least four nationally significant cyberattacks every week, and he has cautioned that number could rise if the UK becomes more directly involved in the wider Iran conflict.
Corroborating Evidence from Anonymized Telemetry
Nozomi Networks Labs telemetry over the past six weeks shows the same pattern at the perimeter. Across participating customers, the large majority of alerts tied to Iran-affiliated activity map to exploitation of internet-facing systems (MITRE ATT&CK® T1190), consistent with early-stage probing rather than deep intrusion.

In one case, a North American water treatment operator drew repeated interest across a two-week span: the Nozomi platform raised four reputation and reconnaissance alerts that traced back to a hosting block with a long history of abuse. Nothing in the telemetry indicates the activity reached the operator’s control systems. These are early-stage, network-level detections, thought the kind of activity a small facility has the best chance of catching before it becomes an incident if basic network monitoring is in place.

To be clear about what this does and doesn’t mean: there is no evidence that every small generator is being hunted. The point is that the risk profile for small facilities has changed. A capability demonstration doesn’t require an important target, only an accessible one, and small facilities are more likely to be accessible: they sit below regulatory reporting thresholds, they rely on remote access because staffing demands it, and they rarely have anyone watching the OT network. The aggregate exposure is not small either: independent scanning by CloudSEK counted roughly 30,000 internet-facing Modbus control devices in the UK alone, each discoverable with the same public search tools an attacker would use.
The Playbook for IRGC-Affiliated Threat Actors: No Zero-Day Required
Neither the UK government nor the National Cyber Security Centre has attributed this incident to a named group, and full attribution is a difficult process in general. What we can do is study the best-documented IRGC-affiliated actor targeting small operational technology facilities: the group calling itself CyberAv3ngers, because its history shows how little sophistication an operation like this requires:
- In November 2023, CISA and its partners documented CyberAv3ngers compromising internet-exposed Unitronics Vision PLCs and HMIs at US water utilities, including the Municipal Water Authority of Aliquippa in Pennsylvania. The initial access technique was a default password: 1111. The actors compromised at least 75 devices across multiple sectors.
- In December 2024, researchers tied the group to IOCONTROL (also called OrpaCrab), a malware family built specifically for OT and IoT devices, and Nozomi Networks Labs later observed the group reusing infrastructure from that campaign.
- In February 2024, the US Treasury sanctioned six IRGC Cyber-Electronic Command officials and the State Department offered a $10 million reward for information on them. In the campaign described in CISA advisory AA26-097A, IRGC-affiliated actors accessed internet-exposed Rockwell Automation controllers using the vendor's own legitimate engineering software. The access itself needed no exploit, no malware, and no CVE, just the vendor's own software pointed at a controller that was reachable from the internet. As Nozomi Networks Field CISO Markus Mueller put it recently, they didn't need a zero-day; they just used the manual.
- In an update to that advisory in July 2026, CISA went further: at one victim the actors altered a controller's project file to disable critical shutdown and alarm logic, letting the system reach unsafe conditions without alerting operators. The same activity has since been observed against Schneider Electric and Siemens controllers, not just Rockwell.
The common threads across all of these incidents: internet exposure, default or weak credentials, legitimate tools and protocols, and targets chosen for accessibility rather than importance. Regardless of who took that UK plant offline, this is the class of tradecraft that defenders should assume could target them: it’s cheap, repeatable and aimed at facilities exactly like the one that just spent four days offline.
Peaker Plants: Essential for Modern Grid Reliability
The UK facility that was shut down for four days hasn’t been identified, but the public description tells us the category of asset involved, and it is one worth understanding because it has quietly become central to how Britain keeps supply and demand in balance. A "small-scale energy generator" of this kind fits the profile of a peaker plant: a unit built not to run around the clock, but to start quickly and run for short periods when demand climbs or when wind and solar output falls away.
Peaker plants rely on speed, not scale. In Great Britain, they are usually open-cycle gas turbines or reciprocating engines. Gas peakers can reach full output in minutes. While individually dispensable, their collective availability maintains grid stability, as Britain increasingly depends on distributed generators to support the renewable grid.
That distributed model creates new risk, because these small-scale generators make attractive targets. Peaker plants are designed to be dispatched on short notice. Many of them sit below the capacity thresholds that would make them regulated Operators of Essential Services, so they carry lighter reporting duties and, in practice, often lighter security budgets. And there are a lot of them, spread across the country, each a small target on its own. Each plant in turn has multiple control systems that can be targets. They manage different parts of the plant, from the fuel system to the turbine control, boiler systems, electric protection relays, metering and environmental monitoring. Sometimes these systems are interconnected, but often they are not.
What was impacted in the July shutdown matters to safety and reliability. Reports indicate that the attack path involved a PLC that was not secured in accordance with basic best practices. This could have been one of the ancillary systems, not the main control system. This is not to say it’s not important to run the plant. For example, if the PLC was connected to a well or water storage tank and an attacker takes it offline, it still will cause the plant to shut down.
None of this requires the attackers to have singled out a peaker on purpose. It simply means the assets most exposed to this class of threat activity are increasingly the ones a modern grid depends on to stay flexible. The resilience that protected the grid this time was engineered for the failure of large, visible plants.
Peaker or Not, Small Facilities Can Take Simple Steps to Protect Themselves
Most small facilities don’t have a security operations center or an OT security engineer; instead, they rely on operators and help from IT to protect their operations. Remote access and lean staffing aren’t negligence; they’re how these sites stay viable. The steps below are chosen for that reality: most are free, and none require specialized staff.
- Find out if you are reachable from the internet. Search your public IP ranges on Shodan. Include cellular modems and any vendor remote access, not just connections your own team installed.
- Change default credentials on anything that touches control. The 2023 CyberAv3ngers campaign required nothing more than a four-digit factory password.
- Filter who can connect remotely. If a site needs remote access to operate, restrict that access to known addresses. IP filtering on a cellular modem is often a simple configuration change.
- Use the physical mode switch. Many controllers have a hardware Run mode that blocks remote modification. Where it exists, use it, and treat changing it as a deliberate maintenance action.
- Keep offline backups of PLC logic and configurations. Four days of restoration is much longer without a known-good copy of your own programs.
- Connect before you need help. UK operators can register for the NCSC's free Early Warning notification service and should know how to report an incident before there is one. Sector information-sharing bodies exist for exactly this purpose.
The Department for Energy Security and Net Zero (DESNZ) has already briefed energy sector executives and signaled that regulation is coming. That will take time, and it will likely land first on operators large enough to regulate. In the meantime, facilities below that threshold will need to lean on each other: share what you see with your peers, your sector bodies and the NCSC.
The UK grid passed this test because engineers spent decades designing it to survive the loss of any single piece. Small facilities deserve the same design philosophy at their own scale: assume something will be compromised and build resilience so the compromise is survivable.
For Nozomi Networks Customers: What to Look For
For readers already running the Nozomi Networks platform, several checks map directly to the tradecraft described above:
- Confirm your Threat Intelligence is current. Labs is continuously updating detections for Iran-affiliated actors; detection coverage details are on the support portal.
- Query your asset inventory for internet reachability. Look for controllers and gateways reachable directly, through jump hosts, or through cellular modems, and prioritize anything carrying default credentials. If you have Vantage IQ, you can simply ask it to identify exposed assets and provide prioritized remediation steps.
- Watch the early-stage techniques. Default credential abuse, valid account anomalies, brute force and scanning are the top techniques Nozomi Networks Labs is observing in current Iran-linked activity. Treat clusters of these as reconnaissance, and if you use Vantage IQ, ask for additional context on the alerts page.
- Hunt for engineering sessions that don't belong. Sessions from unexpected workstations or geographies, off-hours logic uploads or downloads, and traffic to controllers on ports 44818, 2222, 502, 102, 22 and 20256 (Unitronics) from outside expected zones align with the T0883 initial access and T1565 impact mapping in CISA advisory AA26-097A.
- Run the published IOCs against historical traffic, using the indicator lists in the July 8, 2025 (Threat Actor Activity Related to the Iran Conflict) and March 2, 2026 (Iranian APT Activity During Geopolitical Escalation) blog posts cited earlier, along with the refreshed IP list in CISA AA26-097A (updated July 2026):
- Revisit muted alerts. Escalation periods are precisely when a muted alert is most likely to be the one that mattered.
Nozomi Is Here to Help You
In the modern world, global and regional conflicts are always accompanied by the increased activity of cyberthreat actors. Tracking them daily in addition to exercising fundamental all-year-round due diligence is essential to staying resilient and making sure your organization has the best cybersecurity posture possible.
As we continue our mission to safeguard critical infrastructure, we invite organizations worldwide to join us in the fight against cyberattacks by sharing insights that can help strengthen collective defenses for all. For direct assistance, please contact us today.








