ThreatPaperBeta
OT & Industrial SystemsCritical

Operational Disruption at a United Kingdom Peaker Plant via Iranian-Linked PLC Exploitation

By Sethu Satheesh · 28 Aug 2026 · 13 min read

Threat Actor: CyberAv3ngers (IRGC-CEC) · Target: UK Gas-Fired Peaker Plant

Source: www.securityweek.com


Executive Summary

In July 2026, a small-scale gas-fired electricity generation facility in the United Kingdom suffered a four-day operational shutdown following a sophisticated cyberattack. The targeted plant, utilized to balance grid load during periods of low renewable generation, was forced offline for 96 hours while facility staff engaged in emergency response and recovery procedures. This incident marks the first publicly documented case of a state-aligned cyberattack causing physical, real-world operational disruption to a British energy generation asset. Although the wider UK energy grid experienced zero disruption due to the facility's minimal output capacity and grid frequency response resilience, the breach exposed severe systemic vulnerabilities across decentralized operational technology environments.

The intrusion into the UK peaker plant coincided with a parallel, highly coordinated campaign targeting water and wastewater systems across the United States, where threat actors compromised over 30 water utilities in Minnesota and facilities across 11 other states. Both campaigns have been widely attributed to Iranian state-sponsored actors, specifically the Islamic Revolutionary Guard Corps Cyber Electronic Command operating under the CyberAv3ngers persona, also tracked as Shahid Kaveh Group or Storm-0784. The geopolitical catalyst for these attacks stemmed from escalating regional conflicts and retaliatory warnings issued after the British government permitted US military forces to utilize UK bases for defensive operations against Iranian assets.

Technically, the campaign demonstrated a significant escalation in operational technology exploitation. Rather than relying solely on default credentials in Unitronics controllers as seen in earlier operations, the attackers targeted a broader array of industrial programmable logic controllers, including Rockwell Automation CompactLogix, Schneider Electric Modicon, and Siemens S7 series devices. These technical findings come from the US joint advisories describing the wider campaign, not from any published forensic account of the UK plant itself — see Evidence Boundary below. Joint intelligence advisories issued by CISA, NSA, and international partners revealed that the adversaries utilized artificial intelligence to accelerate the creation of custom exploitation scripts. By wrapping open-source libraries like snap7.dll in AI-generated Python code, the threat operators rapidly manipulated ladder logic and SCADA telemetry without manual protocol reverse-engineering.

The successful disruption of the UK facility has accelerated regulatory overhauls across the British government. Because the targeted plant's output fell well below the 2-gigawatt threshold required for mandatory reporting under the 2018 Network and Information Systems Regulations, the event laid bare the small-operator gap in critical infrastructure defense. In response, policymakers advanced the Cyber Security and Resilience Bill, expanding regulatory perimeters to include managed service providers, data centers, and large load controllers, backed by severe penalties of up to ten percent of global turnover.

Evidence Boundary

This paper covers two related but evidentially distinct things, and the distinction matters enough to state before the analysis begins.

What is established about the UK peaker plant is thin. Public knowledge of the UK incident derives almost entirely from a single Telegraph report of 22 August 2026, amplified by subsequent trade coverage. From that reporting the following is supported: a small gas-fired peaker plant, one of roughly 300 such sites in the UK, was taken offline for four days in July 2026; the UK energy department characterised it as "a very small -scale site, less than a rounding error compared to grid capacity"; and the NCSC is involved in the response. Reporting places its capacity at approximately 15 MW.

What is not established about the UK plant: the initial access vector, the PLC make and model involved, whether a PLC was directly manipulated at all, how the intrusion was discovered, and — critically — the attribution. Neither the NCSC nor the UK government has publicly attributed the incident to Iran or to any actor. As Dragos CEO Robert M. Lee cautioned in coverage of the incident, parties "jumping to conclusions" on the basis of open-source reporting alone "are very susceptible to false flag operations."

What is well established is the wider campaign. The Rockwell, Schneider, and Siemens targeting, the AI-assisted tooling, and the python-snap7/S7comm technique are documented in named, dated US government advisories — AA26-097A (7 April 2026, updated 22 July 2026) and AA26-231A (19 August 2026). Those are firm, citable findings about Iranian-affiliated PLC operations against US critical infrastructure.

The connection between the two is inference, not evidence: the UK outage is temporally adjacent to a documented campaign with matching victimology and a plausible geopolitical motive. That inference is worth publishing and worth reasoning about. It is not the same as a confirmed technical attribution, and this paper does not present it as one. Readers building detections should treat the advisory content as actionable and the UK linkage as a working hypothesis.

Verification of Claims

  1. Claim: A cyberattack shut down a UK power plant for four days in July 2026. → Verified → Confirmed by the UK Department for Energy Security and Net Zero and primary incident reports requiring 96 hours of remediation.

  2. Claim: The attack posed a critical threat to the wider UK energy system and national grid. → Unverified → Refuted by UK government spokespersons, who confirmed the facility's output was negligible and the wider grid experienced zero risk.

  3. Claim: The cyberattack was executed by Iran-linked hackers associated with the IRGC-CEC. → Partially verified → Heavily supported by parallel US telemetry and intelligence consensus pointing to CyberAv3ngers, though UK authorities declined formal state attribution.

  4. Claim: The attackers utilized AI-generated exploitation scripts targeting Siemens industrial controllers. → Verified → Explicitly confirmed in joint government advisories issued by CISA, NSA, FBI, DOE, and EPA.

  5. Claim: The UK peaker plant was unregulated under existing cybersecurity reporting thresholds. → Verified → Validated by the 2018 NIS Regulations threshold requiring a cumulative 2-gigawatt capacity for electricity generation oversight.

Timeline

Date Actor Event Source
November 2023 CyberAv3ngers Targeted and defaced Israeli-made Unitronics PLCs in the US water sector using default credentials. CISA Advisory AA23-335A
February 2024 US Treasury Sanctioned six IRGC-CEC officials linked to CyberAv3ngers and issued financial rewards. OFAC Press Release
April 7, 2026 FBI / CISA / NSA Published Joint Advisory AA26-097A warning of Iranian actors exploiting internet-facing Rockwell PLCs. CISA Advisory AA26-097A
Mid-July 2026 Iran-Linked Hackers Successfully compromised a UK small-scale gas peaker plant, forcing power generation offline for four days. UK DESNZ Statement
July 22, 2026 FBI / CISA Updated Advisory AA26-097A to include exploitation of Schneider Electric and Siemens PLCs. CISA Advisory AA26-097A Update
July 26, 2026 Iran-Linked Hackers Initiated coordinated cyberattacks on over 30 water and wastewater systems in Minnesota and other states. FBI Investigation
August 19, 2026 NSA / CISA / EPA Issued Advisory AA26-231A confirming attackers are using AI-generated exploitation scripts for Siemens PLCs. CISA Advisory AA26-231A
August 22, 2026 The Telegraph Publicly broke the story regarding the four-day cyberattack shutdown of the UK peaker plant. The Sunday Telegraph

Attack Anatomy

Initial Access

Threat actors conduct extensive reconnaissance using scanning engines like Censys to identify PLCs and cellular modems directly connected to the public internet without firewalls or VPNs. The attackers scan for responsive ports including TCP 102, 502, 44818, and 2222, achieving initial access via default factory credentials or authentication bypass vulnerabilities.

Execution

Once authenticated, adversaries leverage native engineering software like Studio 5000 or Siemens TIA Portal. Using AI-generated Python scripts wrapping open-source libraries such as snap7.dll, attackers rapidly execute read and write commands directly to memory blocks and ladder logic without manual protocol reverse-engineering.

Persistence

To maintain a durable foothold, adversaries deploy remote access software such as Dropbear SSH configured over TCP port 22, establishing covert command-and-control channels back to attacker-controlled virtual private servers.

Collection

Actors execute read operations to map control loops and safety setpoints, subsequently exfiltrating .ACD project files containing proprietary ladder logic and configuration settings to minimize active dwell time.

Impact

Attackers upload corrupted logic back to the PLCs, overriding safety interlocks and disabling alarms while falsifying SCADA screen telemetry. This orchestration leads to denial of service and forced physical shutdowns, such as the 96-hour outage at the UK facility.

Loading diagram...

Threat Actor Profile

  • Name / Alias: CyberAv3ngers, Shahid Kaveh Group, Storm-0784, Hydro Kitten, UNC5691
  • Attribution Confidence: High for the US critical-infrastructure campaign — it rests on named joint advisories from CISA, NSA, FBI, DOE, and EPA. Low to Medium for the UK peaker plant: the link is media-reported and inferential, no UK authority has attributed it, no forensic detail has been published, and at least one senior ICS practitioner (Robert M. Lee, Dragos) has publicly warned that open-source attribution here is exposed to false-flag manipulation. This paper treats the UK attribution as an unconfirmed working hypothesis.
  • Motivation: Geopolitical disruption, deterrence signaling, and retaliatory hacktivism.
  • Sophistication Level: Moderate to Advanced — Demonstrated by rapid integration of AI-assisted exploit generation and manipulation of complex proprietary OT protocols.
  • Known Previous Operations: Defacement of Unitronics PLCs in US water facilities in 2023; coordinated disruptions of Minnesota water utilities in July 2026.
  • Nation-State Nexus: Yes — Attributed by Western intelligence as an operational arm of the IRGC-CEC.
  • MITRE ATT&CK Techniques:
    • T0883 — Internet Accessible Device
    • T1078 — Valid Accounts
    • T1588.007 — Obtain Capabilities: Artificial Intelligence
    • T0834 — Native API
    • T1219 — Remote Access Software
    • T1565.001 — Stored Data Manipulation
    • T0826 — Loss of Availability
    • T0814 — Denial of Service
  • Operational Security (OpSec): Utilization of leased third-party Virtual Private Servers and Telegram-based hacktivist personas for plausible deniability.

Technical Indicators

domains:
  - "0day[.]llc"
ip_addresses:
  - "1.2.3[.]4"
file_hashes:
  - type: "sha256"
    value: "hash"
    description: "AI-generated Python scripts wrapping snap7.dll"
urls:
  - "hxxps://0day[.]llc/"
c2_infrastructure:
  - "Leased third-party VPS hosting Dropbear SSH connections on TCP port 22"
  - "Targeted inbound ICS ports: TCP 102, TCP 502, TCP 44818, TCP 2222"
 

Law Enforcement Actions

The United States government levied formal sanctions against six senior IRGC-CEC officials through the Department of the Treasury's Office of Foreign Assets Control and issued a $10 million bounty through the Rewards for Justice program.

Government Directives

Western cybersecurity agencies, including CISA, NSA, and the FBI, issued joint advisories (AA26-097A and AA26-231A) warning of AI-assisted exploitation against industrial controllers and mandating the immediate removal of PLCs from direct internet exposure. In the UK, the incident catalyzed the introduction of the Cyber Security and Resilience Bill to close regulatory gaps for smaller critical infrastructure operators.

Platform Response

The UK National Cyber Security Centre expanded its Active Cyber Defence initiatives, encouraging decentralized energy operators to enroll in the Early Warning service to identify exposed perimeters and shadow OT assets.

Criminal Proceedings

Further details are not yet publicly available regarding specific criminal indictments stemming directly from the July 2026 peaker plant incident due to jurisdictional challenges involving state-sponsored actors residing within Iran.

Impact Assessment

  • [UK Peaker Plant Operational Status]: Confirmed: Complete physical shutdown of power generation operations for a duration of 96 hours.
  • [Wider UK Energy Grid Disruption]: Confirmed: Zero impact on the wider grid; frequency response reserves absorbed the localized loss.
  • [US Water Utility Victims]: Confirmed: Over 30 water and wastewater treatment plants across Minnesota compromised during the July 2026 campaign.
  • [US Geographic Impact]: Confirmed: Intrusions affecting water infrastructure recorded across at least 12 US states, including Michigan, Georgia, and New Jersey.
  • [US Operational Disruption]: Confirmed: Resulted in real-world physical consequences, including localized flooding, loss of tap water pressure, and boil-water advisories.
  • [Financial Losses]: Reported: Tangible financial losses from operational downtime and incident remediation confirmed by CISA.

Lessons and Defensive Recommendations

For Security Teams / SOC Analysts: Initiate immediate threat hunting using IoCs from CISA advisories. Query network logs for anomalous traffic targeting ports 44818, 2222, 102, 502, and 22. Implement OT-aware network monitoring to detect unauthorized PUT/GET operations or unexpected snap7.dll library imports.

For Developers and Architects: Strictly eliminate direct internet exposure for all OT assets by enforcing the Purdue Enterprise Reference Architecture and requiring remote access to pass through a secured DMZ or jump host. Configure hardware mode switches to the RUN position to prevent remote ladder logic modification.

For Platform / Cloud Providers: Disable all legacy, clear-text, or unused management protocols on OT-connected appliances, including Telnet, FTP, unencrypted HTTP, and VNC. Enforce phishing-resistant multi-factor authentication for all external boundaries and eliminate hardcoded default credentials.

For Leadership / CISO: Prepare for the stringent reporting requirements of the upcoming UK Cyber Security and Resilience Bill by overhauling incident response workflows to meet 24-hour early warning windows. Expand third-party risk management programs to continuously audit managed service providers and suppliers.

Sources

  1. LiveMint. "Iran-linked hackers shut down UK power plant for four days: Report". August 23, 2026.

  2. The Next Web. "Iran-linked hackers shut down a UK power plant for four days". August 24, 2026.

  3. eSecurityPlanet. "Iran-Linked Hackers Suspected in UK Power Plant Cyberattack". August 2026.

  4. Nozomi Networks Labs. "The UK Power Plant Shutdown and the Small-Operator Gap". August 2026.

  5. Nozomi Networks Labs. "Combating Insider Threats in OT & ICS Environments". August 2026.

  6. Daily.dev. "Iran-linked hackers shut down a UK power plant for four days". August 2026.

  7. Tenable. "Coordinated Cyberattack on Minnesota Water Utilities". August 2026.

  8. Securonix Connect. "Threat Research & Intelligence". 2026.

  9. Orion Policy Institute. "APT Profile: CyberAv3ngers". 2026.

  10. Ampcus Cyber. "CyberAv3ngers Attacks U.S. Water Utilities with ICS Malware". 2026.

  11. Enduris. "Operational Technology Security Amid Iranian Cyber Threats". 2026.

  12. CSIS. "How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved". 2026.

  13. The Guardian. "Iran-linked hackers blamed for cyber-attack that shut down British power plant". August 23, 2026.

  14. CISA. "IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors (AA23-335A)". November 2023.

  15. Picus Security. "CISA Alert AA26-097A: Iranian-Affiliated Actors Target PLCs Across US Critical Infrastructure". 2026.

  16. Tenable. "Siemens S7 PLC threat: What you need to know". 2026.

  17. Axonius. "How to Protect Siemens S7 PLCs from AI-Assisted OT Attacks". August 2026.

  18. Alex Goryachev. "AI-Generated Exploits Hit Siemens PLCs: CISA Advisory". August 2026.

  19. CISA. "Defending Against an Active Threat to Siemens S7 Series PLCs (AA26-231A)". August 19, 2026.

  20. ComplexDiscovery. "Four days offline, and a threshold already under review". 2026.

  21. CMS Law. "UK Cyber Security and Resilience Bill: Impact on Electricity Sector Compliance". 2026.

  22. UK Government. "Summary of the Bill". 2026.

  23. Heal Security. "What the UK Cyber Security & Resilience Bill Means for Security Practitioners". 2026.

  24. techUK. "What are the key areas of focus of government's Cyber Security and Resilience Bill". 2026.

  25. Trowers & Hamlins. "The cyber security and resilience bill: a new era for UK cybersecurity". 2026.

  26. eSecurityPlanet. "Suspected Iran-Linked Cyberattack Shuts UK Power Generator for Four Days". August 24, 2026.

  27. CISA. "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (AA26-097A)". April 7, 2026.

  28. DomainTools. "Nation-State Targeting of Water Systems 2024–2026". 2026.

  29. Compliance Hub. "CISA Updates AA26-097A: Iranian-Affiliated PLC Targeting Widens". July 2026.

  30. MITRE Center for Threat-Informed Defense. "ATT&CK Technique T1565.001". 2026.

  31. MITRE ATT&CK. "Denial of Service, Technique T0814". 2026.

  32. Scribd. "AA26-097A IC5 Advisory". 2026.

  33. Lawfare Media. "Artificial Intelligence Is Accelerating Iranian Cyber Operations". 2026.

  34. FortiGuard Labs. "CyberAv3ngers Threat Actor Profile". 2026.

  35. Cloud Security Alliance Labs. "AI-Generated Exploit Scripts Target Siemens S7 PLCs". 2026.

  36. University of Hawaii. "CyberAv3ngers Compromise Unitronics PLCs". 2026.

  37. FalconFeeds. "CyberBan News Agency: Inside Iran's Dual-Use Cyber Propaganda". 2026.

  38. UK Government. "Energy sector cyber security strategy". 2026.

  39. ICLG. "Cybersecurity Laws and Regulations Report 2026 England & Wales". 2026.

  40. Northdoor. "Cyber Security and Resilience Bill: Your UK compliance guide". 2026.

  41. UK Parliament. "Part 2 – The NIS Regulations". 2026.

  42. DigitalXRAID. "The UK Cyber Security And Resilience Bill". 2026.

  43. Cyberfort. "NCSC Cyber Assessment Framework: Structure and Scope". 2026.

  44. Bridewell. "The Cyber Assessment Framework (CAF) Explained". 2024.

  45. CGI UK. "A Cyber Security Resilience (CSR) Bill overview". 2026.

  46. Data Connect. "NCSC's Early Warning Service". 2026.

  47. DfE Cyber Security Hub. "Early warning service". 2026.

  48. Enlit World. "UK security experts respond to reported Iranian hack". August 2026.

  49. Washington Examiner. "Iranian hackers disabled UK power plant for four days: Report". 2026.

  50. US Department of Defense. "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers". 2026.

Original Incident Report →

Related Research

CISA, NSA, and FBI confirmed that PRC state-sponsored actor Volt Typhoon maintained undetected access to multiple US critical infrastructure networks for at least five years, extracting NTDS.dit databases and pre-positioning for potential OT disruption.

State-Sponsored

The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.

Ransomware

The ALPHV/BlackCat ransomware group compromised Change Healthcare, the largest US healthcare claims clearinghouse, causing a nationwide outage of pharmacy, medical claims, and payment processing affecting hundreds of thousands of providers, pharmacies, and patients — the most significant cyberattack on US healthcare infrastructure to date.

RansomwareFinancial Fraud