A July 2026 cyber incident disrupted a small UK gas-fired electricity generator for several days, prompting a government and NCSC response while posing no wider grid threat or customer outage. Public reporting linked the event to Iran, but no technical evidence has confirmed attribution, and the exact intrusion path, affected systems, and responsible actor remain unknown. #NCSC #Iran #UK #ElectricityGenerator
Keypoints
- The incident affected a small UK electricity generator and caused several days of operational unavailability.
- UK authorities said there was no threat to the wider grid and no customer outages.
- Media reporting described the asset as a roughly 15 MW gas-fired peaking plant, but the operator and location were not disclosed.
- Public claims linked the event to Iran-linked actors, but no NCSC technical advisory has confirmed a specific group or technical evidence.
- The article places the incident in a broader context of elevated threats to UK critical infrastructure and energy systems.
- Related U.S. incidents show ongoing targeting of internet-connected PLCs and other OT environments across critical sectors.
- The main security concern is the exposure of smaller, remotely managed energy assets that can be disrupted even without affecting the wider grid.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â The article describes attacks on internet-facing PLCs and remote-access systems, which implies exploitation of exposed services (âinternet-accessible PLC and HMI systemsâ, âinternet-connected PLCsâ).
- [T1021 ] Remote Services â Attackers may have leveraged remote-management pathways or VPN-style access to reach energy environments (âremote accessâ, âremote sessionsâ, âremote-management infrastructureâ).
- [T1133 ] External Remote Services â The text repeatedly highlights externally reachable OT assets and remote access through gateways and VPN appliances (âexternally reachable OT assetsâ, âVPN appliancesâ, âremote access should be routed through controlled gatewaysâ).
- [T1005 ] Data from Local System â The article mentions attackers changing PLC passwords, IP configurations, and potentially controller project files, indicating interaction with local device settings (âchanging passwords and IP configurationsâ, âmonitor changes to PLC configuration, passwords, IP addresses, project filesâ).
- [T1562 ] Impair Defenses â The incident may have involved containment actions or manipulation of access paths that reduced availability, and the article stresses attacker disruption of monitoring/control (âloss of monitoring or controlâ, âtaken offline as part of containmentâ).
- [T0881 ] Modify Controller Tasking â The article notes the possibility of direct manipulation of PLC logic or generation equipment, though not confirmed (âwhether attackers directly manipulated generation equipment, PLC logicâ).
- [T0842 ] Network Denial of Service â The outage is described as operational unavailability that could have resulted from disruption rather than direct physical control (âresulted in, or contributed to, several days of operational unavailabilityâ).
- [T1082 ] System Information Discovery â Reported activity included reconnaissance of connected systems and equipment scope expansion (âtargeted reconnaissanceâ, âexpanded the observed equipment scopeâ).
- [T1580 ] Obtain Capabilities â The article describes adversaries developing capability against PLCs and using AI-generated exploitation scripts (âcapability developmentâ, âAI-generated exploitation scripts disguised as legitimate monitoring toolsâ).
- [T1595 ] Active Scanning â The mention of internet-facing and exposed controllers implies scanning and identification of reachable OT assets (âinternet-facing Rockwell Automation MicroLogix PLCsâ, âexternally reachable OT assetsâ).
Indicators of Compromise
- [Organizations] Affected and referenced entities â UK electricity generator, NCSC, FBI, EPA, NSA, CISA, Department of Energy
- [Product types] OT/ICS equipment mentioned in threat reporting â Rockwell Automation MicroLogix PLCs, Siemens S7-series PLCs, HMI systems
- [Vendor names] Controllers and industrial vendors referenced â Rockwell Automation, Schneider Electric, Siemens
- [Groups/actors] Attributed or suspected actors â CyberAv3ngers, IRGC-linked actors, Russiaâs FSB Centre 16
- [Geographic/sectoral scope] Target environments and sectors â UK critical national infrastructure, Polandâs energy grid, U.S. water and wastewater utilities